Digital globe with red network connections

SD-Access

Transform the campus through identity-based policy and controlled segmentation.

Overview

An SD-Access assessment goes beyond moving switches into a fabric. User, application and device access requirements, addressing and coexistence boundaries belong in the same design. The objective is to make the organisation’s agreed access rules operational across wired and wireless networks. The small-site reference below makes those decisions tangible; it is not a final design or bill of materials for your organisation.

Underlay, overlay and fabric roles

Existing routing and IP reachability provide the fabric’s transport foundation. Software compatibility, uplink capacity and MTU requirements must be reviewed together. Fabric edges attach endpoints, borders provide external connectivity, and control-plane nodes manage endpoint location information. Reference models may combine roles on the same device. Device counts in a drawing therefore do not establish capacity or redundancy guarantees. Assess role placement against site scale, dependencies and operational boundaries.

CISCO · Figure 29

Cisco SD-Access: small-site topology

Figure 29 of the Cisco design guide shows campus connectivity, the colocated border/control-plane pair, fabric edges and the wireless services block together.

Remainder of Campus NetworkEdge firewall AFirewall pair shown in the remainder of the campus in the source figure.Edge firewall BThe second firewall in the pair shown by the source.Catalyst CenterCampus management and automation component. This figure does not depict management sessions as cabling.ISE PAN / MnTISE administration and monitoring personas in the remainder of the campus.DHCP · DNS · ADShared services grouped together on the campus side in the original figure.Campus routingRouting node shown between the upper campus connection and the two BN/CP nodes.BN / CP ABorder and control-plane roles share one device; the source shows a crosslink to the other BN/CP.BN / CP BSecond colocated border/control-plane node with alternate physical paths to edges and the services block.Local ISE PANThe local ISE node connected to the services block is labelled ISE PAN in the source; its role has not been changed.WLCWireless controller linked to the services block by a Layer 2 port-channel in the reference design.Services blockSwitch-stack or StackWise Virtual services block; routed links to both BN/CP nodes and a Layer 2 WLC link are shown.Fabric edge AFabric edge linked to both BN/CP nodes and a wired client in the source.Fabric edge BFabric edge linked to both BN/CP nodes and the fabric access point.Fabric edge CFabric edge linked to both BN/CP nodes and the second wired client.Fabric APAP cabled to edge B. Wireless clients are shown with radio symbols in the source, not wired connections.Wired clientWired endpoint attached to fabric edge A in the source.Wired clientWired endpoint attached to fabric edge C in the source.Wireless clientWireless endpoint from the source; no physical cable has been added.Wireless clientSecond wireless endpoint from the source; no physical cable has been added.BN: Border node · CP: Control plane · AP: Access point · MnT: Monitoring
  • Routed link
  • Access / Layer 2 link
Explore the diagram

Select a node to read its role. Drag to pan or use the buttons to zoom.

Cisco's small-site physical reference model. BN and CP are colocated on two nodes; WLC and local ISE connect through the services block. No VN or SGT segments absent from the source have been added.

Segmentation and identity readiness

Document an access matrix: which user or device groups require each application, and which flows must be denied? Treat virtual-network boundaries and group-based permissions as separate decisions. Identity-based microsegmentation requires ISE integration, certificates and 802.1X flows to be included in the pilot. Do not assume printers, cameras and user computers share the same authentication behaviour. Record exception ownership, justification and review dates rather than allowing broad access indefinitely.

Dependencies before migration

Assign owners for DHCP, DNS, NTP, identity services, administrative access and external connectivity. Document how each currently working application flow will traverse the fabric. Separate areas requiring coexistence with legacy VLANs from areas that can migrate completely. Rollback must cover addressing, wireless access and application-owner validation as well as device configuration.

Pilot and acceptance scenarios

Start with a representative building, floor or user group. Define measurable acceptance steps for wired access, wireless roaming, guest connectivity and critical applications. Test denied flows as well as permitted ones. Establish expected behaviour when an identity service or uplink is unavailable. Compare results with the baseline; a healthy device indicator does not by itself establish end-to-end service acceptance.

Operational handover and change control

Handover should include the role-based topology, access matrix, administrative permissions, rollback steps and alarm owners. Operators must be able to trace an access issue through authentication, policy and the data path. Recording policy changes, maintaining configuration backups and planning maintenance windows matter as much as installation. A scoped assessment with Trustnet establishes product selection, implementation steps and support responsibilities against the actual environment.

Technology Partners

All technology partners

Services

  • Consulting and Assessment

    We assess your existing infrastructure and business requirements, recommend suitable technology and support optimization and implementation. Our consultancy covers networks, data centers, unified communications, security and network optimization.

  • Architecture Design

    We plan, implement and commission network, server and security infrastructure. Scope includes data centers, virtualization, storage, backup and disaster recovery, with handover and ongoing management where agreed.

  • Deployment and Integration

    We address network, system and security deployment from site readiness through controlled transition and operational handover.