Make the current network and dependencies visible
Transformation starts with workflows, before a device list. Record the networks used by employees, printers, cameras and critical applications. Assign owners to IP pools, DHCP, DNS, NTP, identity services and external connections. Two devices sharing a VLAN do not necessarily need the same access. Compare inventory with observed traffic and record a successful baseline. This helps distinguish changes introduced by the pilot from problems that already existed.
Validate the underlay and fabric roles
Cisco SD-Access uses Catalyst Center for management, LISP for the control plane, VXLAN for the data plane and TrustSec for policy. Assess these responsibilities alongside hardware, software and licensing compatibility. Plan edge, border and control-plane roles for capacity and redundancy. Define tests for underlay reachability, MTU and external connectivity. Routing at the fabric boundary must account for data centre, internet and WAN services. A healthy device is insufficient evidence that the campus works: application flows need separate validation.
Cisco SD-Access: small-site topology
Figure 29 of the Cisco design guide shows campus connectivity, the colocated border/control-plane pair, fabric edges and the wireless services block together.
- Routed link
- Access / Layer 2 link
Select a node to read its role. Drag to pan or use the buttons to zoom.
Cisco's small-site physical reference model. BN and CP are colocated on two nodes; WLC and local ISE connect through the services block. No VN or SGT segments absent from the source have been added.
Tie policy to identity and application needs
Virtual networks organise logical separation while security groups organise permitted relationships. Design Cisco ISE authentication and authorisation with certificate infrastructure and device diversity in mind. Document exceptions for devices that cannot authenticate; broad access should not become a permanent workaround. Obtain required resources and ports from application owners. Test denied paths as well as permitted ones. Defined ownership and review dates turn segmentation into an operating practice rather than a one-time configuration.
Test coexistence through a bounded pilot
Limit the first scope to a representative but manageable user group or floor. Prepare acceptance scenarios for wired and wireless access, roaming, guests and critical applications. Define coexistence boundaries between legacy VLANs and the fabric; extend Layer 2 only where needed. Agree on decision makers and rollback thresholds before the change window. Test identity service and connectivity failures alongside successful flows. Evaluate device evidence, application tests and user feedback together.
Make operational handover part of the design
After a successful pilot, order migration waves by application criticality. Current topology, access matrices, rollback steps and alarm ownership belong in the handover. Operators should trace a user access issue through authentication, policy and the data path. Assign responsibility for access transfer, configuration backups and policy review. Plan post-change monitoring and acceptance decisions in advance. A discussion with Trustnet can clarify current network constraints, business priorities and a practical transition scope.



