1. Reference architecture by security zone
Untrust — transports & WAN edge
DMZ — reachable from outside
Trust — campus fabric + services block
2. Control-plane relationships (who talks to whom)
3. Endpoint onboarding → policy → enforcement (wired, SD-Access)
4. The portfolio in one table
| Plane | Products | Ties to |
|---|---|---|
| Campus switching | Catalyst 9200 / 9300(X) / 9400(X) / 9500(X) / 9600(X), IE3x00/9300, Cat1200/1300, legacy 3850/4500/6500 | Fabric roles, ISE (802.1X/TrustSec), Catalyst Center, SNA (NetFlow/ETA), MACsec |
| Enterprise routing | Catalyst 8200/8300/8500/8000V, ISR 1000/4000, ASR 1000, IR 1101/1800/8x00 | SD-WAN (controller mode), DMVPN/FlexVPN, ZBFW/Snort, fusion/border, Cloud OnRamp |
| Wireless | Catalyst 9800-80/40/L/CL/SW, EWC, 9100 APs (Wi-Fi 6/6E/7), CW dual-persona, Meraki MR | Fabric wireless, ISE (EAP/CWA/iPSK), guest anchor (DMZ), Spaces, aWIPS |
| Intent & assurance | Catalyst Center (appliance/VA/cloud), Cisco Networking Cloud, Prime (legacy) | Everything via NETCONF/REST/pxGrid; ISE, SD-WAN Manager, ThousandEyes, IPAM, ITSM |
| SD-Access | CP / Border / Edge / Intermediate / Fabric WLC / Extended nodes / Transits / Fabric-in-a-Box; VN + SGT; LISP + VXLAN-GPO | Catalyst Center (orchestrates), ISE (policy), fusion FW (inter-VN), SD-WAN transit |
| SD-WAN | Manager, Validator, Controller, Analytics, cEdges, Cloud OnRamp, MRF, AppQoE, SD-Routing | Umbrella/Secure Access SIG, SD-Access transit, ThousandEyes, Meraki unified dashboard |
| Identity & policy | ISE (PAN/PSN/MnT/pxGrid/PIC), TrustSec (SGT/SGACL/SXP), Duo, Secure Access, Umbrella, Secure Client | All NAS devices, AD/PKI, firewalls, SNA, SIEM |
| Observability | Catalyst Center Assurance, ThousandEyes, SNA/ETA, AVC/NBAR2, MDT/gNMI, NetFlow/IPFIX, Splunk, AppDynamics, XDR | Feeds from every device; quarantine back through ISE |
| Automation | NETCONF/RESTCONF/gNMI/YANG, Intent APIs, NSO, Ansible/Terraform providers, pyATS, CML, PnP/ZTP, EEM, Guest Shell, IOx | Git → CI → controllers/devices; validation pre/post |
| Licensing | SLUP, DNA Essentials/Advantage/Premier, CSSM / SSM On-Prem, Meraki per-device | Features unlock (SD-Access needs Advantage); air-gap needs SSM On-Prem |
| Security edge | Secure Firewall FTD/FMC/ASA, Secure Access, Umbrella, XDR, Hypershield, Cyber Vision, Talos | Internet edge + fusion PEP; pxGrid context; OT visibility |
5. Design choices compared
SD-Access vs Campus EVPN vs Classic 3-tier
- SD-Access: LISP + VXLAN-GPO; Catalyst Center + ISE mandatory; VN/SGT end-to-end; best ZT story; hardest to troubleshoot blind
- Campus EVPN-VXLAN: BGP EVPN on Cat9k; standards-based; manual SGT; needs BGP skills
- Classic + VRF-Lite + TrustSec: simplest, most manual; common in air-gapped enclaves
SD-WAN vs DMVPN/FlexVPN vs MPLS-only
- SD-WAN: OMP control plane, app-aware routing, ZTP, on-prem controllers OK for DoD
- DMVPN/FlexVPN: no controllers, IKEv2 CNSA suites, still preferred on many classified edges
- MPLS-only: provider-trusted, no encryption, no app steering
Catalyst Center vs SD-WAN Manager vs Meraki vs NSO
- Catalyst Center = LAN/WLAN/fabric intent + assurance (heavy, on-prem)
- SD-WAN Manager = WAN overlay only (3-node + DR)
- Meraki Dashboard = cloud-only, simpler, limited DoD use
- NSO = multi-vendor transactional service orchestration
HA patterns
- Access: StackWise / dual-sup SSO
- Dist/Core: StackWise Virtual or routed ECMP pair
- Fabric: 2+ CPs (Pub/Sub), 2 borders, anycast GW
- WLC: 9800 HA SSO (RMI+RP)
- ISE: 2 PAN/MnT + N PSN + node groups
- Catalyst Center: 3-node cluster + DR
- SD-WAN: Manager ×3 (+DR), Validator ×2, Controller ×2; dual edges + dual transport
6. Lab build-out tiers (Cisco-native → open source)
Tier 1 — Bare minimum
FTDv · Cat8000V · Cat9kv Fabric-in-a-Box · ISE standalone · Catalyst Center VA (optional) · 9800-CL (+1 AP)
1 untrustfw leg5 trustTier 2 — Every role once
Adds FMCv, transport router, Manager/Validator/Controller, hub + branch cEdge, fusion FTDv, Border+CP, 2 edges, branch FiaB, extended node, fabric WLC, guest anchor, SNA, services
2413Tier 3 — Pragmatic HA (worth it)
Dual border/CP, 9800 SSO pair, ISE small deployment, FTDv HA pair, Validator×2 + Controller×2, hub cEdge pair w/ TLOC-ext, 3rd color + impairment
4617Tier 4 — Over-built HA (costs learning)
Catalyst Center 3-node + DR, Manager cluster + DR, MRF regions, ISE medium, SNA Data Store, 2nd fabric site, F5 pair, Splunk cluster (~2 TB RAM)
rehearsal onlyOSS Tier 1
OPNsense · VyOS · FRR+OVS · PacketFence · OpenWISP+OpenWrt · Samba AD/Unbound/Kea/chrony/step-ca · client
OSS Tier 2
+ flexiWAN/OpenZiti, SONiC-VS border, 2 FRR edges, hub/branch VyOS, NetBox+AWX+Oxidized+Batfish, ElastiFlow/Zeek/Suricata, Grafana/Prometheus, Wazuh, Smokeping
OSS Tier 3
+ OPNsense CARP, dual EVPN RR, OpenWISP behind HAProxy, PacketFence cluster, dual VyOS hub + 2 transports, FreeRADIUS HA, keepalived VIPs
7. Build order (dependencies)
8. Compliance at a glance
| Component | STIG / SRG | FIPS | CNSA | ZTA pillar | Vanta-catalog evidence |
|---|---|---|---|---|---|
| Cat9k / Cat8k IOS-XE | IOS XE NDM · L2S · RTR STIGs | FIPS mode, 140-3 modules | MACsec/SSH AES-256-GCM, P-384 certs, IKEv2 CNSA | Network, Device, Visibility | 800-53 AC/AU/CM/IA/SC; 800-171/CMMC 3.1/3.3/3.4/3.13; PCI 1/2/4/10; ISO 27001 A.8 |
| 9800 WLC / APs | WLC STIG, WLAN SRG, 8420.01 | FIPS | WPA3-Ent 192-bit (GCMP-256) | Device, User | AC-18, CJIS, HIPAA transmission |
| ISE | ISE STIG / AAA SRG | FIPS (irreversible) | EAP-TLS P-384, RadSec | User, Device (PDP) | IA-2/5, AC-2/3, PCI 8, CJIS adv-auth |
| Catalyst Center | ASD / Web SRG + vendor hardening | FIPS at install | TLS CNSA suites | Automation, Visibility | CM-2/6, CA, RA; CIS 1/4; COBIT change mgmt |
| SD-WAN | SD-WAN NDM/RTR STIGs | FIPS all parts | IPsec AES-256-GCM/SHA-384 | Network, Data | SC-8/12/13, DORA resilience, NIS 2 |
| SNA / Splunk / ThousandEyes | Application SRG; FedRAMP SaaS where applicable | — | — | Visibility & Analytics | AU-6/SI-4/IR-4, NIST CSF Detect, GDPR Art.32, PCI 10/11 |