Index

A

ABB (Architecture Building Blocks), 47

access (authorized), example of IBN, 225226

access layer, 4

access port configuration, 135, 196, 207

access requests, architecture frameworks, 233235

access switches

configuration, 125126, 160161

failures, 45

accounting, RADIUS, 293

action plans, 143, 146

action lists, 144

analysis, 144

decision lists, 144

estimated timelines, 144145

management summaries, 143

Activation process (IBN), 81

ad hoc operations (organizational maturity), 138

ADM (Architecture Development Method), 43

phases of, 4345

requirements management, 45

Agile software engineering methodology, 3334

analysis (action plans), 144

analytics, 312

application behavior analytics, 112113

architecture frameworks, 232

Cisco DNA, 59, 6566

MDT, 316318, 320

NetFlow, 318320

network analytics, 111, 120121

Ansible, 118119

application behavior analytics, 112113

DNAC Assurance, 113115

NetBrain, 117118

network function analytics, 111112

network services availability, 112

Prime Infrastructure, 115117

trend analysis, 112

validation of Intent, 111

network function analytics, 111112

SNMP, 312314, 320

Syslog, 314316, 320

anchor controller deployments, 15

Ansible

component overview of, 105106, 108

control engine, 106

control tower, 107108

network analytics, 118119

network automation, 105108

playbooks, 107

AP (Access Points), 1011

AR and, 216

CAPWAP tunnels, 1011

Mobility Express, 1415

API (Application Program Interface)

calls, matching to tools, 219

Cisco DNA, 7071

concept API definitions, 218

definitions, 218

Intent-based API, 215217

network intents

API calls, matching to tools, 219

concept API definitions, 218

generalizing, 217218

identifying, 217

service catalogs, 219223

Prime Infrastructure, 116

service catalogs, 219223

APIC-EM (Application Policy Infrastructure Controller-Enterprise Module), 100101

day-0 operations, 169171

PnP, 284285

App-Credits use case, 225

applications

architectures, 42, 230

behavior analytics, 112113

business-supported apps/portals (communication plans), 223

enterprise building example (application organization), 130132

AR (Augmented Reality), 215216

architecture frameworks, 231232

application architectures, 230

benefits of, 3839

building blocks, 231

business architectures, 230

change, possibility of, 231

Cisco DNA, 51

analytics, 59, 6566

API, 7071

automation, 58, 6265

Cisco DNA-ready infrastructures, 6869

cloud service management, 5758

conceptual overview of, 5657

design principles, 6073

identity, 5859

infrastructure, 59

open standards, 6970

overview of Cisco solutions, 7374

policies, 6667

requirements, 5156

RESTful API, 71

routed ports, 6869

security, 5960, 7173

software, 6667

switchports, 6869

VNF, 6061

data architectures, 230

defined, 3739

digitalization, 246247

DIY architectures, 49

drawbacks of, 39

enterprise architectures

drawbacks of, 39

guidelines/principles, 46

flexibility, 231

IBN, impact of, 232

access requests, 233235

analytics, 232

automation, 232

Cloud Service Management, 232

infrastructure, 232235

implementation of, 231

layered approach of, 229230

overview of, 4849

repositories, 4748

reusability, 231

serviceability, 231

technology architectures, 230231

TOGAF®, 3941, 48

ADM, 4345

application architectures, 42

aspects of, 4041

building blocks, 4647

business architectures, 4142

data architectures, 42

technology architectures, 4243

Assurance process, 8182, 162166

asymmetric SSH key authentication and Ansible, 106107

authentication

asymmetric SSH key authentication and Ansible, 106107

IEEE 802.1X network access control standard, 291293

RADIUS, 293

Authentication Server (IEEE 802.1X), 291

Authenticator (switch), IEEE 802.1X, 291

authorization

IBN, authorized access, 225226

RADIUS, 157, 293

VLAN, 157158

Autoconf, 207

automation, 174

architecture frameworks, 232

build pipelines, 33

Cisco DNA, 58, 6265

classic VLAN, 9091, 185

configuration changes, 173

day-0 operations, 169172

day-1 operations, 174

day-2 operations, 173

day-n operations, 167169

IBN, transitioning to, 166167

LAN, 189190

network automation, 111, 119120

Ansible, 105108

APIC-EM, 100101

Cisco DNAC, 97100

custom-built automation tools, 109111

defined, 9597

NSO, 101103

Prime Infrastructure, 100101

Puppet Enterprise, 103105

SWIM, 167

switch upgrades, 169

availability of resources, 150151

B

baselines, 187188

classic VLAN, 193199

SDA, 188189

LAN automation, 189190

manual configuration, 190193

bootstrap templates, 170172

border nodes

dynamic VLAN, 190

SDA, 86

BPDU (Bridge Protocol Data Unit) packets, 1617

BPDU Guard, 1718

breakouts

central controller with

central breakout deployments, 1213

FlexConnect deployments, 1314

local controller with local breakout deployments, 13

budget (prioritizing challenges in IBN transitions), 142

build pipelines (automated), 33

building blocks (architecture frameworks), 4647, 231

business

architectures, 4142, 230

communication plans 222

processes and digitalization, 238

supported apps/portals (communication plans), 223

C

calls (API), matching to tools, 219

campus networks

Agile software engineering methodology, 3334

Cloud Edge infrastructures, 3032

cloud infrastructures, 3032

cloud-managed networks, 1920

collapsed core/two-tier topologies, 89

complexity of, 2829

connected devices (IoT/non-user operated devices), 2627

development of, 2326

DevOps, 3234

digitalization, 35

functional layers, 4

access layer, 4

core layer, 56

distribution layer, 45

hardware, inventories, 133134, 152

IBN, transitioning to, 129

access port configuration, 135

action plans, 143146

Assurance process, 162166

automation, 166167

baselines, 187199

challenges to day-to-day operations, 129132, 145

change procedures, 149

classic VLAN, 184187

configuration standardization, 160162

converting intents, 200202

day-0 operations, 169172

day-1 operations, 174

day-2 operations, 173

day-n operations, 167169

design/configuration documentation, 149

disaster recovery, 149

enterprise building example (application organization), 130132

extracting intents, 201202

generic IT visions/strategies, 149

incident management, 149

inventories, 132134, 145, 152

investment plans, 152155

lab environments, 179181, 187

level of standardization, 134138, 141142, 145, 155

lifecycle management, 149, 152155

matching requirements, 148

network infrastructure requirements, 151155

organizational maturity, 138140, 145

organizational requirements, 148155

port-centic to policy-centric design migration, 155159

prioritizing challenges, 142143

resource availability, 150151

risks of, 149, 174176

SDA, 181184

shared switch configuration, 135

standardization across locations, 137138

upgrade plans, 151152

uplink standardization, 135136

vendor/product selection, 149

visibility, 162166

VLAN configuration standardization, 136137

VLAN numbering, 159160

wired campus design, 134

wireless campus design, 134135

manageability of, 2930

NetDevOps, 3435

redundancy, handling, 1619

security, 29

shared switch configuration, 135

single switch topologies, 910

software, inventories, 133, 152

three-tier topologies, 68

toolchains, 3435

trends in, 2326

wired design, 134

wireless design, 134135

CAPWAP (Control and Provisioning of Wireless Access Points) tunnels, 1011

catalogs, network intents service, 219220

business-supported apps/portals, 223

pilots/proof of concepts, 222

sharing successes/failures, 221222

understanding a business, 222

CDB (Configuration Database) and NSO, 101102

central controller with

central breakout deployments, 1213

FlexConnect deployments, 1314

challenges

change management, 276277

day-to-day operations, 129132, 145

prioritizing in IBN transitions, 142143

chance of success (prioritizing challenges in IBN transitions), 142

change

change management, 271272, 281

challenges, 276277

communication, 276

failures, 277

fear of change, 274

focus, maintaining, 276

forward thinking, 277278, 281

governance, 279280

incentives, 274275

learning stages of a new skill, 272273

lifecycle management, 280

ownership, 281

ownership, taking, 278279

positivity, 281

quid pro quo, 274275

speed of change, 281

stakeholders, 279280

training, 281

training/demonstration, 279

enterprise architectures, 231

procedures, 149

CICD (Continuous Integration/Continuous Delivery), 3334

Cisco Design Thinking Framework, 243245

Cisco DNA (Digital Network Architecture), 51, 77. See also IBN

analytics, 59, 6566

API, 7071

architecture frameworks, 232

access requests, 233235

analytics, 232

automation, 232

Cloud Service Management, 232

infrastructure, 232235

automation, 58, 6265

cloud service management, 5758

conceptual overview of, 5657

design principles, 6073

functions of, 213214

identity, 5859

infrastructures, 59, 6869

open standards, 6970

overview of Cisco solutions, 7374

policies, 6667

requirements, 5156

RESTful API, 71

routed ports, 6869

security, 5960, 7173

software, 6667

switchports, 6869

VNF, 6061

Cisco DNAC (DNA Center), 97100

API, 215

Assurance process, 162166

DNAC Assurance, 113115

SDA, 182183

CiscoLive Europe intent API use case, 215216

classic VLAN (Virtual Local Area Networks), 184

automation, 185

baselines, 193199

IBN and, 8891

Layer 2 intents, 185

overlay networks, 186

Scalable Group Tags, 185

SDA and, 183187

SDA topologies, 9091

templates, 186

testing, 186

VRF-Lite distribution switches, 184

Cloud Edge infrastructures, 3032

cloud

Cloud Service Management

architecture frameworks, 232

Cisco DNA, 5758

infrastructures, 3032

networks, 1920

COBIT (Control Objectives for Information and related Technologies), 138

ad hoc operations, 138

defined/documented processes/responsibilities, 139

framework summary, 139140

internal control, 139

intuitive operations, 138

optimization, 139

quality checks, 139

repetitive operations, 138

risk management, 139

version control, 139

collapsed core/two-tier topologies, 89, 8990

commitment (prioritizing challenges in IBN transitions), 142

communication

change management, 276

plans, 221222

business-supported apps/portals, 223

pilots/proof of concepts, 222

successes/failures, sharing, 221222

understanding a business, 222

complexity of campus networks, 2829

compromise, IoC, 223224

concept API definitions, 218

configuration

access port configuration, 135, 196

access switches, 125126, 160161

automation and configuration changes, 173

CDB and NSO, 101102

design/configuration documentation, 149

distribution switches, 124, 126, 161

generic (global) configuration, shared switch configuration, 135

global (generic) configuration, standardization, 160162

Layer 3 configuration, shared switch configuration, 135

links, 191

loopback(), 191192

NTP, 161

ports, shared switch configuration, 135

SDA baselines, 190193

shared switch configuration, 135

Syslog, 161

underlay routing, 192

uplink port configuration, 196

VLAN, 136137, 161162

wireless networks, 161162

connected devices (IoT/non-user operated devices)

connections per capita, 27

growth of, 2627

control (internal), organizational maturity, 139

control nodes, SDA, 86

controllers

anchor controller deployments, 15

central controller with central breakout deployments, 1213

local controller with local breakout deployments, 13

wireless controllers, Cisco DNAC Assurance, 166

core layer, 56

CSI (Continual Service Improvement), 255256

custom-built automation tools, 109111

CVD (Cisco Validated Designs), 3

D

data architectures, 42, 230

day-0 operations, 169172

day-1 operations, 174

day-2 operations, 173

day-n operations, 167169

day-to-day operations, challenges to, 129132, 145

defined/documented processes/responsibilities (organizational maturity), 139

demonstration/training, change management, 279

deployments, wireless networks, 15

anchor controller deployments, 15

central controller with

central breakout deployments, 1213

FlexConnect deployments, 1314

local controller with local breakout deployments, 13

Mobility Express, 1415

design

Design Thinking, 242245

documentation, 149, 221

network design, 247248

DevOps, 3235, 257258

DHCP (Dynamic Host Configuration Protocol)

DHCP option 43, PnP, 285286

enterprise building example (application organization), 131

LAN automation, 190

PnP

day-0 operations, 170

DHCP option 43, 285286

ZTP and, 287288

digitalization, 3435

business processes, 238

defined, 237238

enterprise architectures, 246247

IBN and, 245246

model of, 238239

organizational impact, 246

enterprise architectures, 246247

network design, 247248

network operation, 248249

stages of, 239, 241

business and IT alignment, 239

IT as business enabler, 240

IT change business processes, 241

IT proactive support of business, 240241

disaster recovery, 149

distance-vector routing protocol, 299

distribution layer, 4

distribution switches

configuration, 124, 126, 161

VRF-Lite distribution switches, 184

DIY enterprise architectures, 49

DNA (Digital Network Architecture), 51, 77. See also IBN

analytics, 59, 6566

API, 7071

architecture frameworks, 232

access requests, 233235

analytics, 232

automation, 232

Cloud Service Management, 232

infrastructure, 232235

automation, 58, 6265

cloud service management, 5758

conceptual overview of, 5657

design principles, 6073

functions of, 213214

identity, 5859

infrastructures, 59, 6869

open standards, 6970

overview of Cisco solutions, 7374

policies, 6667

requirements, 5156

RESTful API, 71

routed ports, 6869

security, 5960, 7173

software, 6667

switchports, 6869

VNF, 6061

DNAC (DNA Center), 97100

API, 215

Assurance process, 162166

DNAC Assurance, 113115

PnP, 286

SDA, 182183

DNS (Domain Name System), enterprise building example (application organization), 131

documentation

design/configuration documentation, 149, 221

organizational maturity, 139

dynamic VLAN (Virtual Local Area Networks), border nodes, 190

E

edge nodes, SDA, 8586

enterprise architectures, 231232

application architectures, 230

building blocks, 231

business architectures, 230

change, possibility of, 231

data architectures, 230

digitalization, 246247

DIY architectures, 49

drawbacks of, 39

flexibility, 231

guidelines/principles, 46

implementation of, 231

layered approach of, 229230

overview of, 4849

repositories, 4748

reusability, 231

serviceability, 231

technology architectures, 230231

TOGAF®, 3940, 48

ADM, 4345

application architectures, 42

aspects of, 4041

building blocks, 4647

business architectures, 4142

data architectures, 42

technology architectures, 4243

enterprise building example (application organization), 130132

estimated timelines (action plans), 144145

Ethernet and STP, 308310, 320

examples of IBN (Intent-Based Networking), 223

authorized access, 225226

incident response security, 223224

organizing meetings, 224225

extended IBN (Intent-Based Networking)

locations, 202203

security, 204

IEEE 802.1X network access control standard, 205208

risks, 209

scalability, 210

Scalable Group Tags, 208209

training, 210211

transitioning to SDA, 209210

F

fabrics, SDA, 85, 87

failures

access switches, 45

change management, 277

communication plans, sharing, 223

fear of change, 274

FinTech Ltd. use case, 25

automation, 64

communication and focus in change management, 276

DIY architectures, 49

IBN technologies, choosing, 186

intents, extracting, 201202

first hop security, 196

FlexConnect, central controller with FlexConnect deployments, 1314

flexibility, enterprise architectures, 231

focus, maintaining in change management, 276

forward thinking, change management, 277278, 281

frameworks (architecture), 231232

application architectures, 230

benefits of, 3839

building blocks, 231

business architectures, 230

change, possibility of, 231

Cisco Design Thinking Framework, 243245

Cisco DNA, 51

analytics, 59, 6566

API, 7071

automation, 58, 6265

Cisco DNA-ready infrastructures, 6869

cloud service management, 5758

conceptual overview of, 5657

design principles, 6073

identity, 5859

infrastructure, 59

open standards, 6970

overview of Cisco solutions, 7374

policies, 6667

requirements, 5156

RESTful API, 71

routed ports, 6869

security, 5960, 7173

software, 6667

switchports, 6869

VNF, 6061

data architectures, 230

defined, 3739

digitalization, 246247

DIY architectures, 49

drawbacks of, 39

enterprise architectures

drawbacks of, 39

guidelines/principles, 46

flexibility, 231

IBN, impact of, 232

access requests, 233235

analytics, 232

automation, 232

Cloud Service Management, 232

infrastructure, 232235

implementation of, 231

IT operations frameworks, 263

CSI in ITIL framework, 255256

DevOps, 257258

ITIL framework, 252256

Lean IT, 258263

overusing, 252253

ITIL framework, 252

layered approach of, 229230

overview of, 4849

repositories, 4748

reusability, 231

serviceability, 231

technology architectures, 230231

TOGAF®, 3941, 48

ADM, 4345

application architectures, 42

aspects of, 4041

building blocks, 4647

business architectures, 4142

data architectures, 42

technology architectures, 4243

frequency band (unlicensed spectrum), 26

functional layers, 4

access layer, 4

core layer, 56

distribution layer, 45

G

generic (global) configuration

shared switch configuration, 135

standardization, 160162

generic IT visions/strategies, 149

governance in change management, 279280

H

hardware, inventories, 133134, 152

human change, 271272, 281

challenges, 276277

communication, 276

failures, 277

fear of change, 274

focus, maintaining, 276

forward thinking, 277278, 281

incentives, 274275

learning stages of a new skill, 272273

ownership, 281

ownership, taking, 278279

positivity, 281

quid pro quo, 274275

speed of change, 281

training, 279, 281

I

IBN (Intent-Based Networking), 77, 213215). See also Cisco DNA

Activation process, 81

API, 215217

calls, matching to tools, 219

concept API definitions, 218

definitions, 218

generalizing network intents, 217218

identifying network intents, 217

network Intent service catalogs, 219223

architecture frameworks, IBN impact on, 232

access requests, 233235

analytics, 232

automation, 232

Cloud Service Management, 232

infrastructure, 232235

Assurance process, 8182, 162166

classic VLAN, 8891

collapsed core/two-tier topologies, 8990

design requirements, 8384

digitalization and, 245246

enterprise building example (application organization), 130132

examples of, 223

authorized access, 225226

incident response security, 223224

organizing meetings, 224225

extended IBN

locations, 202203

security, 204211

feedback

intent-based feedback, 82

network-driven feedback, 8184, 93

intent

defined, 7880

example of, 78

intent-based feedback, 82

network-based intents, 7980

overview of, 7879

requesting, 81

metrics, 82

microsegmentation, 83, 93

network analytics, 111, 120121

Ansible, 118119

application behavior analytics, 112113

DNAC Assurance, 113115

NetBrain, 117118

network function analytics, 111112

network services availability, 112

Prime Infrastructure, 115117

trend analysis, 112

validation of Intent, 111

network automation, 111, 119120

Ansible, 105108

APIC-EM, 100101

Cisco DNAC, 97100

custom-built automation tools, 109111

defined, 9597

NSO, 101103

Prime Infrastructure, 100101

Puppet Enterprise, 103105

network-based intents, 7980

perspective, 8083

policy-centric networks, 83, 93

SDA, 84, 91

border nodes, 86

classic VLAN over SDA topologies, 9091

control nodes, 86

design choices, 8889

edge nodes, 8586

example of, 8688

fabrics, 85, 87

operation of, 8688

overview of, 8485

underlay networks, 8586

virtual networks, 85

security, IEEE 802.1X network access control standard, 205208

systematic approach to networks, 80

transitioning to, 129

access port configuration, 135

action plans, 143146

Assurance process, 162166

automation, 166167

baselines, 187199

challenges to day-to-day operations, 129132, 145

change procedures, 149

classic VLAN, 184187

configuration standardization, 160162

converting intents, 200202

day-0 operations, 169172

day-1 operations, 174

day-2 operations, 173

day-n operations, 167169

design/configuration documentation, 149

disaster recovery, 149

extracting intents, 201202

generic IT visions/strategies, 149

incident management, 149

inventories, 132134, 145, 152

investment plans, 152155

lab environments, 179181, 187

level of standardization, 134138, 141142, 145, 155

lifecycle management, 149, 152155

matching requirements, 148

network infrastructure requirements, 151155

organizational maturity, 138140, 145

organizational requirements, 148155

port-centic to policy-centric design migration, 155159

prioritizing challenges, 142143

resource availability, 150151

risk management, 149

risks of, 174176

SDA, 181184

shared switch configuration, 135

standardization across locations, 137138

tips for success. See change management

upgrade plans, 151152

uplink standardization, 135136

vendor/product selection, 149

visibility, 162166

VLAN configuration standardization, 136137

VLAN numbering, 159160

wired campus design, 134

wireless campus design, 134135

Translation process, 82

validation, 82

visibility, 162166

identity, Cisco DNA, 5859

IEEE 802.1b, 23

IEEE 802.1X network access control standard, 156157, 290291, 319

access port configuration, 207

authentication process, 291293

Authentication Server, 291

Authenticator (switch), 291

components of, 291292

IBN security, 205208

RADIUS, 196, 205, 292293

supplicants, 291

implementation of enterprise architectures, 231

incentives, change management, 274275

incidents

management, 149

response security, example of IBN, 223224

infrastructure

architecture frameworks, 232235

Cisco DNA, 59

Prime Infrastructure, 97100, 115117, 170

requirements (networks), 151155

installations (next-next-finish), 157

intent API (Application Program Interface), 215217

Intent-Based Networking. See IBN

intents

IBN, transitioning to

converting intents, 200202

extracting intents, 201202

Layer 2 intents, classic VLAN, 185

network intents

API calls, matching to tools, 219

concept API definitions, 218

generalizing, 217218

identifying, 217

service catalogs, 219223

internal control (organizational maturity), 139

intuitive operations (organizational maturity), 138

inventories, transitioning to IBN, 132134, 145, 152

investment plans, 152155

IoC (Indication of Compromise), 223224

IoT (Internet of Things), growth of, 27

IP address pools, LAN automation, 189190

IPv6, first hop security, 196

ISE (Identity Services Engine), 157

port-centic to policy-centric design migration, 159

SDA, 183

IS-IS, underlay routing configuration, 192

IT operations

conflicts/recommendations

changing design patterns, 264, 268

management by exception, 265266, 268269

organizational change, 266267, 270

working across domains, 266, 269270

digitalization

business and IT alignment, 239

IT as business enabler, 240

IT change business porcesses, 241

IT proactive support of business, 240241

frameworks, 263

CSI in ITIL framework, 255256

DevOps, 257258

ITIL framework, 252256

Lean IT, 258263

overusing, 252253

ITIL framework, 252

overusing frameworks, 252253

visions/strategies (generic), 149

L

lab environments, 179181, 187

LAN (Local Area Networks)

automation, 189190

redundancy, handling, 1617

VLAN, 305308, 319

VXLAN, 301302, 319

Layer 2 intents, classic VLAN, 185

Layer 2 networks, redundancy, handling, 1617

Layer 3 configuration, shared switch configuration, 135

Layer 3 networks, redundancy, handling, 17

Lean IT, 258263

learning stages of a new skill, 272273

LEI (Lean Enterprise Institute), 259

lifecycle management, 149, 152155, 280

links, configuration, 191

link-state routing protocol, 299300

LISP (Locator/Identifier Separation Protocol), 302305, 319

lists

action lists, 144

decision lists, 144

local controller with local breakout deployments, 13

locations, extended IBN, 202203

LogiServ Inc. use case

automation, 169

port-centic to policy-centric design migration, 158

standardization and design, 221222

switch upgrades, 169

loopback(), configuration, 191192

M

manageability of campus networks, 2930

management

classic VLAN over SDA topologies, 90

summaries (action plans), 143

VRF, 90

matching API calls to tools, 219

maturity level of an organization, 138, 145

ad hoc operations, 138

defined/documented processes/responsibilities, 139

internal control, 139

intuitive operations, 138

optimization, 139

organizational requirements, 148150

quality checks, 139

questions and related maturity levels, 140

repetitive operations, 138

risk management, 139

version control, 139

MDT (Model-Driven Telemetry), 316318, 320

meetings, organizing, 224225

Meraki, 1920

microsegmentation, IBN, 83, 93

mobility, trends in, 2326

Mobility Express, 1415

MSTP (Multiple Spanning Tree Protocol), 310

N

NAD (Network Access Devices), RADIUS servers, 293

NED (Network Elements Drivers) and NSO, 101

NetBrain, 117118

NetDevOps, 3435

NetFlow, 318320

networks

analytics, 111, 120121

Ansible, 118119

application behavior analytics, 112113

DNAC Assurance, 113115

NetBrain, 117118

network function analytics, 111112

network services availability, 112

Prime Infrastructure, 115117

trend analysis, 112

validation of Intent, 111

automation, 111, 119120

Ansible, 105108

APIC-EM, 100101

building automation tools, 109111

Cisco DNAC, 97100

defined, 9597

NSO, 101103

Prime Infrastructure, 100101

Puppet Enterprise, 103105

campus networks

access port configuration, 135

action plans and IBN transitions, 143146

Agile software engineering methodology, 3334

Assurance process, 162166

automation, 166167

baselines, 187199

classic VLAN, 184187

Cloud Edge infrastructures, 3032

cloud infrastructures, 3032

complexity of, 2829

configuration standardization, 160162

connected devices (IoT/non-user operated devices), 2627

converting intents, 200202

day-0 operations, 169172

day-1 operations, 174

day-2 operations, 173

day-n operations, 167169

development of, 2326

DevOps, 3234

digitalization, 35

extracting intents, 201202

hardware inventories, 133134, 152

inventories, 133, 145, 152

investment plans, 152155

lab environments, 179181

level of standardization, 134138, 145, 155

lifecycle management, 152155

manageability of, 2930

NetDevOps, 3435

organizational maturity, 138140

port-centic to policy-centric design migration, 155159

prioritizing challenges in IBN transitions, 142143

SDA, 181184

security, 29

shared switch configuration, 135

stakeholders and IBN transitions, 141142, 145

standardization across locations, 137138

toolchains, 3435

transitioning to IBN. See IBN, transitioning to

trends in, 2326

upgrade plans, 151152

uplink standardization, 135136

visibility, 162166

VLAN configuration standardization, 136137

VLAN numbering, 159160

wired design, 134

wireless design, 134135

design, 247248

digitalization, 35

network design, 247248

network operation, 248249

infrastructure requirements, 151155

intents, 7980

API calls, matching to tools, 219

concept API definitions, 218

generalizing, 217218

identifying, 217

service catalogs, 219223

NAD and RADIUS servers, 293

operation of, 248249

overlay networks and classic VLAN, 186

policy-centric networks, port-centic to policy-centric design migration, 155159

services, network analytics, 112

VLAN, 305308, 311312, 319320

VXLAN, 301302, 319

wireless networks

configuration standardization, 161162

connected devices (IoT/non-user operated devices), 2627

development of, 2326

frequency band (unlicensed spectrum), 26

security, 29

trends in, 2326

next-next-finish installations, 157

non-user operated devices

connections per capita, 27

growth of, 2627

NSO (Network Services Orchestrator), 101

CDB and, 101102

NED and, 101

NTP configuration, 102103

schematic overview, 101102

YANG and, 101102

NTP (Network Translation Protocol), configuration, 102103, 161

O

open standards, Cisco DNA, 6970

optimization (organizational maturity), 139

option 43 (DHCP), and PnP, 285286

order pickers, 24

organizational change, 271272, 281

challenges, 276277

communication, 276

failures, 277

fear of change, 274

focus, maintaining, 276

forward thinking, 277278, 281

governance, 279280

incentives, 274275

learning stages of a new skill, 272273

lifecycle management, 280

ownership, 281

ownership, taking, 278279

positivity, 281

quid pro quo, 274275

speed of change, 281

stakeholders, 279280

training, 281

training/demonstration, 279

organizational maturity, 138, 148150

ad hoc operations, 138

defined/documented processes/responsibilities, 139

internal control, 139

intuitive operations, 138

optimization, 139

quality checks, 139

questions and related maturity levels, 140

repetitive operations, 138

risk management, 139

version control, 139

organizing

applications, enterprise building example (application organization), 130132

meetings, example of IBN, 224225

overlay networks, classic VLAN, 186

ownership, change management, 278279, 281

P

PacketFence, 158

pilots/proof of concepts (communication plans), 222

playbooks and Ansible, 107

PnP (Plug-n-Play), 288, 319

APIC-EM and, 284285

day-0 operations, 169171

DHCP option 43, 285286

DNAC and, 286

Pokemon Go, 215

policies

Cisco DNA, 6667

policy-centric networks, port-centic to policy-centric design migration, 155159

portals, business-supported apps/portals (communication plans), 223

ports

access port configuration, 135, 196, 207

port-centic to policy-centric design migration, 155159

routed ports

Cisco DNA, 6869

switchports versus, 6869

shared switch configuration, 135

switchports

Cisco DNA, 6869

routed ports versus, 6869

uplink port configuration, 196

positivity, change management, 281

Prime Infrastructure, 97100, 115117, 170

prioritizing challenges in IBN transitions, 142143

processes/responsibilities (organizational maturity), 139

product/vendor selection, 149

proof of concepts/pilots (communication plans), 222

protocols

distance-vector routing protocol, 299

link-state routing protocol, 299300

MSTP, 310

routing protocols, 298300, 319

RSTP, 310

SNMP, 312314, 320

STP, 308310

VTP, 311312, 320

Puppet Enterprise, 103105

Python and ZTP, 288

Q

QoS (Quality of Service), use case, 2829

quality checks (organizational maturity), 139

quid pro quo, change management, 274275

R

RACI matrix, 141

RADIUS,

RADIUS (Remote Access DialUp Services), 293295, 319

IEEE 802.1X, 292293

RADIUS servers, 158

authorization rules, 157

IEEE 802.1X network access control standard, 196, 205

redundancy, handling, 1619

repetitive operations (organizational maturity), 138

repositories (architecture), 4748

requirements

IBN, transitioning to

matching requirements, 148

organizational requirements, 148155

organizational requirements, maturity level of an organization, 148150

resource availability, 150151

responsibilities/processes (organizational maturity), 139

RESTful API, Cisco DNA, 71

reusability, enterprise architectures, 231

RFC 2058, RADIUS, 294295

risk management, 139, 149

routed ports

Cisco DNA, 6869

switchports versus, 6869

routing protocols, 298299, 319

distance-vector routing protocol, 299

link-state routing protocol, 299300

routing (underlay), configuration, 192

RSTP (Rapid Spanning Tree Protocol), 310

S

SBB (Solution Building Blocks), 47

scalability, extended IBN security, 210

Scalable Group Tags. See SGT

SDA (Software-Defined Access), 84, 181184, 284

baselines, 188189

LAN automation, 189190

manual configuration, 190193

border nodes, 86

classic VLAN and, 9091, 183187

control nodes, 86

design choices, 8889

edge nodes, 8586

example of, 8688

fabrics, 85, 87

LISP, 302305, 319

operation of, 8688

overview of, 8485

STP, 185

transitioning to, 209210

underlay networks, 8586

virtual networks, 85

VXLAN, 301302, 319

security

Cisco DNA, 5960, 7173

compromise, IoC, 223224

enterprise building example (application organization), 131

first hop security, 196

IBN, 204

IEEE 802.1X network access control standard, 205208

risks, 209

scalability, 210

Scalable Group Tags, 208209

training, 210211

transitioning to SDA, 209210

incident response example, 223224

IoC, 223224

networks, 29

servers (RADIUS), 293

service catalogs (network intents), 219220

business-supported apps/portals, 223

pilots/proof of concepts, 222

sharing successes/failures, 221222

understanding a business, 222

serviceability, enterprise architectures, 231

SGT (Scalable Group Tags), 295298, 319

classic VLAN, 185

extended IBN, 208209

shared switch configuration, 135

SharedService Group use case, 2829

Cisco DNAC Assurance, 163166

datacenter automation, 110111

digitalization, IT proactive support of business, 240

DNAC Assurance, 163165

IT operation frameworks, overusing, 252253

lab environments, 187

lifecycle management, 153

port-centic to policy-centric design migration, 158

Scalable Group Tags, 208209

virtualizing network functions, 61

VLAN configuration standardization, 136

single switch topologies, 910

skills, learning stages of new, 272273

slow change, change management, 281

small switches, topology of, 308309

SNMP (Simple Network Management Protocol), 312314, 320

software

Agile software engineering methodology, 3334

Cisco DNA, 6667

inventories, 133, 152

SDA, 181184

Spanning Tree Protocol. See STP

speed of change, change management, 281

SSH (Secure Shell), asymmetric SSH key authentication and Ansible, 106107

SSID (Service Set Identifiers), VLAN configuration standardization, 136

stakeholders

change management, 279280

IBN, transitioning to, 141142, 145

RACI matrix, 141

standardization

access switch configuration, 160161

benefits of, 221

design and, 221

distribution switch configuration, 161

global (generic) configuration, 160162

level of, 134138, 145, 155

across locations, 137138

uplinks, 135136

VLAN, 136137, 161162

wireless network configuration, 161162

storage, repositories (architecture), 4748

STP (Spanning Tree Protocol), 308310, 320

classic VLAN over SDA topologies, 90

drawbacks, 1617

SDA and, 185

uplinks, blocking, 1617

successes

chance of success, prioritizing challenges in IBN transitions, 142

communication plans, sharing, 223

supplicants (IEEE 802.1X), 291

SWIM (SoftWare Image Management), 167

switches

access switches

configuration, 125126

configuration standardization, 160161

automating upgrades, 169

distribution switches

configuration, 124, 126

configuration standardization, 161

VRF-Lite distribution switches, 184

shared switch configuration, 135

small switches, topology of, 308309

upgrading, 169

VRF-Lite distribution switches, 184

switchports

Cisco DNA, 6869

routed ports versus, 6869

Syslog, 161, 314316, 320

T

technology architectures, 4243, 230231

templates

bootstrap templates, 170172

classic VLAN, 186

three-tier topologies, 68

time (prioritizing challenges in IBN transitions), 142

timelines (action plans), estimated, 144145

TOGAF® (The Open Group Architecture Framework), 3941, 48

ADM, 43

phases of, 4345

requirements management, 45

application architectures, 42

aspects of, 4041

building blocks, 4647

business architectures, 4142

data architectures, 42

technology architectures, 4243

toolchains, 3435

topologies

collapsed core/two-tier topologies, 89

lab topologies, 180181

single switch topologies, 910

small switches, 308309

three-tier topologies, 68

training

change management, 279, 281

extended IBN, 210211

Translation process (IBN), 82

trend analysis, network analytics, 112

tunnels (CAPWAP), 1011

two-tier/collapsed core topologies, 89, 8990

U

UDLD (Unidirectional Link Detection), 18

underlay networks, SDA, 8586

underlay routing, configuration, 192

understanding a business (communication plans), 222

unlicensed spectrum (frequency band), 26

upgrade plans, 151152

upgrading switches, 169

uplinks

blocking, 1617

port configuration, 196

standardization, level of, 135136

use cases

App-Credits use case, 225

automation, 173

CiscoLive Europe use case, Intent-based API, 215216

configuration and automation, 173

examples of IBN, 223

authorized access, 225226

incident response security, 223224

organizing meetings, 224225

FinTech Ltd. use case, 25

automation, 64

choosing IBN technologies, 186

communication and focus in change management, 276

DIY architectures, 49

extracting intents, 201202

incident response security, 223224

LogiServ Inc. use case

automation, 169

port-centic to policy-centric design migration, 158

standardization and design, 221222

switch upgrades, 169

organizing meetings, 224225

QoS, 2829

quid pro quo, change management, 275

SharedService Group use case, 2829

Cisco DNAC Assurance, 163166

datacenter automation, 110111

DNAC Assurance, 163165

IT proactive support of business, 240

lab environments, 187

lifecycle management, 153

overusing IT operation frameworks, 252253

port-centic to policy-centric design migration, 158

Scalable Group Tags, 208209

virtualizing network functions, 61

VLAN configuration standardization, 136

V

validated designs, 3

vendor/product selection, 149

version control (organizational maturity), 139

virtual networks, SDA, 85

visibility, transitioning to IBN, 162166

VLAN (Virtual Local Area Networks), 305308, 319

authorization rules, 157158

classic VLAN, 184187

automation, 185

baselines, 193199

IBN and, 8891

Layer 2 intents, 185

overlay networks, 186

Scalable Group Tags, 185

SDA and, 183187

SDA topologies, 9091

templates, 186

testing, 186

VRF-Lite distribution switches, 184

configuration standardization, 136137, 161162

dynamic VLAN, border nodes, 190

management VLAN, classic VLAN over SDA topologies, 90

numbering, 159160

VTP, 311312, 320

VNF (Virtualize Network Functions), 6061

vPC (Virtual PortChannel), 1719

VRF (Virtual Routing and Forwarding), classic VLAN over SDA topologies, 90

VRF-Lite (Virtual Routing and Forwarding-Lite), 184, 289290, 319

VSS (Virtual Switching Solutions)

redundancy, handling, 1719

teardowns, 180181

VTP (VLAN Trunking Protocol), 311312, 320

VXLAN (Virtual eXtensible Local Area Networks), 301302, 319

W

WAN (Wide-Area Networks), enterprise building example (application organization), 131

wired design, campus networks, 134

wireless controllers, Cisco DNAC Assurance, 166

wireless design, campus networks, 134135

wireless networks, 11, 15

anchor controller deployments, 15

AP, 1011

CAPWAP tunnels, 1011

central controller with

central breakout deployments, 1213

FlexConnect deployments, 1314

configuration standardization, 161162

connected devices (IoT/non-user operated devices)

connections per capita, 27

growth of, 2627

development of, 2326

frequency band (unlicensed spectrum), 26

local controller with local breakout deployments, 13

Mobility Express, 1415

security, 29

trends in, 2326

WLC, 10

WLC (Wireless LAN Controllers), 10

Y

YAML (YAML Ain’t Markup Language), playbooks and Ansible, 107

YANG (Yet Another Next Generation) and NSO, 101102

Z

ZTP (Zero Touch Provisioning), 288

DHCP and, 287288

operational flow of, 287288

Python and, 288

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.219.86.155