Article
Preparing Campus Networks for SD-Access
Plan SD-Access in five practical steps, from inventory and identity policy to pilot validation and handover.

Transform the campus through identity-based policy and controlled segmentation.
An SD-Access assessment goes beyond moving switches into a fabric. User, application and device access requirements, addressing and coexistence boundaries belong in the same design. The objective is to make the organisation’s agreed access rules operational across wired and wireless networks. The small-site reference below makes those decisions tangible; it is not a final design or bill of materials for your organisation.
Existing routing and IP reachability provide the fabric’s transport foundation. Software compatibility, uplink capacity and MTU requirements must be reviewed together. Fabric edges attach endpoints, borders provide external connectivity, and control-plane nodes manage endpoint location information. Reference models may combine roles on the same device. Device counts in a drawing therefore do not establish capacity or redundancy guarantees. Assess role placement against site scale, dependencies and operational boundaries.
Figure 29 of the Cisco design guide shows campus connectivity, the colocated border/control-plane pair, fabric edges and the wireless services block together.
Select a node to read its role. Drag to pan or use the buttons to zoom.
Cisco's small-site physical reference model. BN and CP are colocated on two nodes; WLC and local ISE connect through the services block. No VN or SGT segments absent from the source have been added.
Document an access matrix: which user or device groups require each application, and which flows must be denied? Treat virtual-network boundaries and group-based permissions as separate decisions. Identity-based microsegmentation requires ISE integration, certificates and 802.1X flows to be included in the pilot. Do not assume printers, cameras and user computers share the same authentication behaviour. Record exception ownership, justification and review dates rather than allowing broad access indefinitely.
Assign owners for DHCP, DNS, NTP, identity services, administrative access and external connectivity. Document how each currently working application flow will traverse the fabric. Separate areas requiring coexistence with legacy VLANs from areas that can migrate completely. Rollback must cover addressing, wireless access and application-owner validation as well as device configuration.
Start with a representative building, floor or user group. Define measurable acceptance steps for wired access, wireless roaming, guest connectivity and critical applications. Test denied flows as well as permitted ones. Establish expected behaviour when an identity service or uplink is unavailable. Compare results with the baseline; a healthy device indicator does not by itself establish end-to-end service acceptance.
Handover should include the role-based topology, access matrix, administrative permissions, rollback steps and alarm owners. Operators must be able to trace an access issue through authentication, policy and the data path. Recording policy changes, maintaining configuration backups and planning maintenance windows matter as much as installation. A scoped assessment with Trustnet establishes product selection, implementation steps and support responsibilities against the actual environment.
We assess your existing infrastructure and business requirements, recommend suitable technology and support optimization and implementation. Our consultancy covers networks, data centers, unified communications, security and network optimization.
We plan, implement and commission network, server and security infrastructure. Scope includes data centers, virtualization, storage, backup and disaster recovery, with handover and ongoing management where agreed.
We address network, system and security deployment from site readiness through controlled transition and operational handover.