Cisco Enterprise Infrastructure — How Everything Ties Together

Campus switching · Enterprise routing · Wireless · Catalyst Center · SD-Access · Catalyst SD-WAN · ISE/TrustSec · Assurance & telemetry · Automation · Licensing — laid out across the three lab/production security zones (Untrust / DMZ / Trust) with the control-plane relationships and the four-tier lab build-outs.

Untrust zone DMZ zone Trust zone Controllers / intent Identity & policy Telemetry / assurance Shared services

1. Reference architecture by security zone

Untrust — transports & WAN edge

Internet / DISN-MPLS / LTE-5GThree SD-WAN "colors": biz-internet, mpls, lte
Catalyst 8500 SD-WAN hub paircEdge; TLOC-extension between hubs; IPsec AES-256-GCM + BFD per tunnel
Branch: Cat8300/8200 cEdge (dual)DIA + ZBFW/Snort; LTE fallback; Fabric-in-a-Box behind it
Secure Firewall FTD (internet edge)NGFW, RA-VPN, NAT; outside NIC here, inside NIC in DMZ
Lab: Cat8000V / VyOS "ISP" + netemSimulates transports and impairment

DMZ — reachable from outside

SD-WAN Validator (vBond) ×2Needs a public/NAT'd IP; first contact for every edge; DTLS
ISE PSN VIP / portals (F5 or HAProxy)Guest/BYOD portals, RadSec front door
9800 Guest Anchor WLCMobility tunnel from foreign WLC; guest exits here
ThousandEyes Enterprise AgentSaaS/Internet/WAN synthetic tests
External DNS · Umbrella/Secure Access tunnelsSIG auto-tunnels from SD-WAN
Fusion Firewall FTD pair (outside NIC)Inter-VN inspection; VRF-Lite eBGP per VN to border

Trust — campus fabric + services block

Border + Control Plane (9500X/9600X SVL)LISP Map-Server/Resolver (Pub/Sub); VXLAN ↔ BGP/VRF-Lite handoff to fusion
Intermediate (9500)Underlay only: IS-IS, /32 loopbacks, ECMP, MTU 9100, PIM-SSM
Edge nodes (9300X stacks / 9400)802.1X/MAB → SGT; Anycast GW; VXLAN-GPO; SGACL egress
Extended / Policy Extended Nodes (IE3400/IE9300)OT/IoT with Cyber Vision sensor
Fabric WLC 9800 HA SSO + 9100 APsCAPWAP control only; AP → VXLAN → edge
Catalyst Center 3-node (+DR)Design/Policy/Provision/Assurance/Fabric; Intent API; SWIM; PnP
SD-WAN Manager ×3 · Controller ×2Config groups, OMP, policy; on-prem for DoD
ISE PAN/MnT ×2 · PSN ×N · pxGrid ×2RADIUS/TACACS+, profiling, posture, SGT matrix, CoA
SNA Manager + Flow Collectors · Splunk/ElasticNetFlow/ETA/MDT/syslog-TLS; ANC quarantine via pxGrid
AD/LDAP · DNS · DHCP · NTP · PKI (CA/CRL/OCSP)Time and certs first
SSM On-Prem · NetBox/Nautobot · Ansible/NSO · GitLicensing (SLUP RUM), source of truth, automation
OOB management (console server, Mgmt-vrf)Manage from outside the fabric you are changing

2. Control-plane relationships (who talks to whom)

Catalyst Center ──NETCONF/SSH/SNMP/PnP/HTTPS──▶ Cat9k · Cat8k · 9800 · IE (Day-0/1/2 provisioning, SWIM) Catalyst Center ──REST/ERS + pxGrid──────────▶ ISE (VNs, SGT matrix, AAA settings) Catalyst Center ──REST──────────────────────▶ SD-WAN Manager · ThousandEyes · IPAM · ITSM · Spaces Catalyst Center ◀──MDT gRPC · NetFlow · syslog · wireless telemetry── devices (Assurance, AI analytics) ISE ◀──RADIUS 1812 / RadSec 2083 / TACACS+ 49── switches · WLC · routers · firewalls (NAS) ISE ──CoA 1700/3799───────────────────────────▶ NAS (re-auth, quarantine) ISE ──pxGrid 8910─────────────────────────────▶ FTD/FMC · SNA · PAN-OS · Splunk · Catalyst Center ISE ──SXP 64999───────────────────────────────▶ non-inline devices (IP→SGT bindings) ISE ◀──LDAPS 636 · Kerberos 88 · WMI────────── Active Directory / LDAP / Entra ID Edge ──LISP 4342──▶ Control Plane node (Map-Register / Map-Request) Edge ⇄ Edge/Border: VXLAN-GPO 4789 (SGT in header) Border ──BGP + VRF-Lite per VN──▶ Fusion FW ──▶ DC · WAN · Internet 9800 ──CAPWAP 5246── fabric AP ──VXLAN──▶ Edge cEdge ──DTLS 12346+──▶ Validator ──▶ Controller (OMP) ──▶ Manager (NETCONF push) cEdge ⇄ cEdge : IPsec AES-256-GCM / GRE per color + BFD 1s ×7 App-aware routing via SLA classes SD-Access VN ⇄ SD-WAN VPN (SD-Access transit) — SGT preserved across the WAN All devices ──SLUP RUM──▶ SSM On-Prem ──(manual sync)──▶ CSSM All devices ──syslog-TLS 6514 · NetFlow 2055 · gNMI 57400──▶ SNA · Splunk · Elastic

3. Endpoint onboarding → policy → enforcement (wired, SD-Access)

[Endpoint] link up ─▶ [Edge 802.1X EAPoL] ─RADIUS EAP-TLS─▶ [ISE PSN] ─LDAPS / CRL-OCSP─▶ [AD · PKI] │ authz: IP pool / VN=CORP · SGT=Employee · dACL ◀─ policy set result ▼ [Edge] Map-Register EID(MAC/IP → RLOC) ─▶ [CP node] Anycast GW answers ARP on every edge [Endpoint] ─▶ [Edge] Map-Request dst ─▶ [CP] ─▶ RLOC ─▶ VXLAN-GPO(VNI=CORP, SGT=Employee) ─▶ [dst Edge] ─SGACL(src,dst)─▶ permit/deny Inter-VN: [Edge] ─▶ [Border] decap ─▶ VRF CORP ─▶ [Fusion FW inspect] ─▶ VRF DC / outside Threat: [SNA / XDR] ─pxGrid ANC─▶ [ISE] ─CoA─▶ [Edge] re-auth ─▶ SGT=Quarantine

4. The portfolio in one table

PlaneProductsTies to
Campus switchingCatalyst 9200 / 9300(X) / 9400(X) / 9500(X) / 9600(X), IE3x00/9300, Cat1200/1300, legacy 3850/4500/6500Fabric roles, ISE (802.1X/TrustSec), Catalyst Center, SNA (NetFlow/ETA), MACsec
Enterprise routingCatalyst 8200/8300/8500/8000V, ISR 1000/4000, ASR 1000, IR 1101/1800/8x00SD-WAN (controller mode), DMVPN/FlexVPN, ZBFW/Snort, fusion/border, Cloud OnRamp
WirelessCatalyst 9800-80/40/L/CL/SW, EWC, 9100 APs (Wi-Fi 6/6E/7), CW dual-persona, Meraki MRFabric wireless, ISE (EAP/CWA/iPSK), guest anchor (DMZ), Spaces, aWIPS
Intent & assuranceCatalyst Center (appliance/VA/cloud), Cisco Networking Cloud, Prime (legacy)Everything via NETCONF/REST/pxGrid; ISE, SD-WAN Manager, ThousandEyes, IPAM, ITSM
SD-AccessCP / Border / Edge / Intermediate / Fabric WLC / Extended nodes / Transits / Fabric-in-a-Box; VN + SGT; LISP + VXLAN-GPOCatalyst Center (orchestrates), ISE (policy), fusion FW (inter-VN), SD-WAN transit
SD-WANManager, Validator, Controller, Analytics, cEdges, Cloud OnRamp, MRF, AppQoE, SD-RoutingUmbrella/Secure Access SIG, SD-Access transit, ThousandEyes, Meraki unified dashboard
Identity & policyISE (PAN/PSN/MnT/pxGrid/PIC), TrustSec (SGT/SGACL/SXP), Duo, Secure Access, Umbrella, Secure ClientAll NAS devices, AD/PKI, firewalls, SNA, SIEM
ObservabilityCatalyst Center Assurance, ThousandEyes, SNA/ETA, AVC/NBAR2, MDT/gNMI, NetFlow/IPFIX, Splunk, AppDynamics, XDRFeeds from every device; quarantine back through ISE
AutomationNETCONF/RESTCONF/gNMI/YANG, Intent APIs, NSO, Ansible/Terraform providers, pyATS, CML, PnP/ZTP, EEM, Guest Shell, IOxGit → CI → controllers/devices; validation pre/post
LicensingSLUP, DNA Essentials/Advantage/Premier, CSSM / SSM On-Prem, Meraki per-deviceFeatures unlock (SD-Access needs Advantage); air-gap needs SSM On-Prem
Security edgeSecure Firewall FTD/FMC/ASA, Secure Access, Umbrella, XDR, Hypershield, Cyber Vision, TalosInternet edge + fusion PEP; pxGrid context; OT visibility

5. Design choices compared

SD-Access vs Campus EVPN vs Classic 3-tier

  • SD-Access: LISP + VXLAN-GPO; Catalyst Center + ISE mandatory; VN/SGT end-to-end; best ZT story; hardest to troubleshoot blind
  • Campus EVPN-VXLAN: BGP EVPN on Cat9k; standards-based; manual SGT; needs BGP skills
  • Classic + VRF-Lite + TrustSec: simplest, most manual; common in air-gapped enclaves

SD-WAN vs DMVPN/FlexVPN vs MPLS-only

  • SD-WAN: OMP control plane, app-aware routing, ZTP, on-prem controllers OK for DoD
  • DMVPN/FlexVPN: no controllers, IKEv2 CNSA suites, still preferred on many classified edges
  • MPLS-only: provider-trusted, no encryption, no app steering

Catalyst Center vs SD-WAN Manager vs Meraki vs NSO

  • Catalyst Center = LAN/WLAN/fabric intent + assurance (heavy, on-prem)
  • SD-WAN Manager = WAN overlay only (3-node + DR)
  • Meraki Dashboard = cloud-only, simpler, limited DoD use
  • NSO = multi-vendor transactional service orchestration

HA patterns

  • Access: StackWise / dual-sup SSO
  • Dist/Core: StackWise Virtual or routed ECMP pair
  • Fabric: 2+ CPs (Pub/Sub), 2 borders, anycast GW
  • WLC: 9800 HA SSO (RMI+RP)
  • ISE: 2 PAN/MnT + N PSN + node groups
  • Catalyst Center: 3-node cluster + DR
  • SD-WAN: Manager ×3 (+DR), Validator ×2, Controller ×2; dual edges + dual transport

6. Lab build-out tiers (Cisco-native → open source)

6

Tier 1 — Bare minimum

FTDv · Cat8000V · Cat9kv Fabric-in-a-Box · ISE standalone · Catalyst Center VA (optional) · 9800-CL (+1 AP)

1 untrustfw leg5 trust
19

Tier 2 — Every role once

Adds FMCv, transport router, Manager/Validator/Controller, hub + branch cEdge, fusion FTDv, Border+CP, 2 edges, branch FiaB, extended node, fabric WLC, guest anchor, SNA, services

2413
27

Tier 3 — Pragmatic HA (worth it)

Dual border/CP, 9800 SSO pair, ISE small deployment, FTDv HA pair, Validator×2 + Controller×2, hub cEdge pair w/ TLOC-ext, 3rd color + impairment

4617
40+

Tier 4 — Over-built HA (costs learning)

Catalyst Center 3-node + DR, Manager cluster + DR, MRF regions, ISE medium, SNA Data Store, 2nd fabric site, F5 pair, Splunk cluster (~2 TB RAM)

rehearsal only
7

OSS Tier 1

OPNsense · VyOS · FRR+OVS · PacketFence · OpenWISP+OpenWrt · Samba AD/Unbound/Kea/chrony/step-ca · client

18

OSS Tier 2

+ flexiWAN/OpenZiti, SONiC-VS border, 2 FRR edges, hub/branch VyOS, NetBox+AWX+Oxidized+Batfish, ElastiFlow/Zeek/Suricata, Grafana/Prometheus, Wazuh, Smokeping

26

OSS Tier 3

+ OPNsense CARP, dual EVPN RR, OpenWISP behind HAProxy, PacketFence cluster, dual VyOS hub + 2 transports, FreeRADIUS HA, keepalived VIPs

7. Build order (dependencies)

1 Hosts + OOB ─▶ 2 NTP ▸ DNS ▸ DHCP ▸ PKI ─▶ 3 AD/LDAP ─▶ 4 Firewalls (edge + fusion, zones) ─▶ 5 Underlay (IGP, /32, MTU 9100, ECMP, PIM-SSM) ─▶ 6 ISE (AD join, certs, policy sets, SGTs) ─▶ 7 Catalyst Center (ISE/IPAM integration, discovery, SWIM) ─▶ 8 SD-Access (CP/Border → Edges → VNs → fusion) ─▶ 9 9800 SSO + APs + guest anchor ─▶ 10 SD-WAN (Validator → Controller → Manager → certs → cEdges → policy → transit) ─▶ 11 Telemetry (MDT, NetFlow/ETA, syslog-TLS → SNA/SIEM, ThousandEyes) ─▶ 12 Licensing + STIG/FIPS evidence ─▶ 13 Git + Ansible/NSO + pyATS validation

8. Compliance at a glance

ComponentSTIG / SRGFIPSCNSAZTA pillarVanta-catalog evidence
Cat9k / Cat8k IOS-XEIOS XE NDM · L2S · RTR STIGsFIPS mode, 140-3 modulesMACsec/SSH AES-256-GCM, P-384 certs, IKEv2 CNSANetwork, Device, Visibility800-53 AC/AU/CM/IA/SC; 800-171/CMMC 3.1/3.3/3.4/3.13; PCI 1/2/4/10; ISO 27001 A.8
9800 WLC / APsWLC STIG, WLAN SRG, 8420.01FIPSWPA3-Ent 192-bit (GCMP-256)Device, UserAC-18, CJIS, HIPAA transmission
ISEISE STIG / AAA SRGFIPS (irreversible)EAP-TLS P-384, RadSecUser, Device (PDP)IA-2/5, AC-2/3, PCI 8, CJIS adv-auth
Catalyst CenterASD / Web SRG + vendor hardeningFIPS at installTLS CNSA suitesAutomation, VisibilityCM-2/6, CA, RA; CIS 1/4; COBIT change mgmt
SD-WANSD-WAN NDM/RTR STIGsFIPS all partsIPsec AES-256-GCM/SHA-384Network, DataSC-8/12/13, DORA resilience, NIS 2
SNA / Splunk / ThousandEyesApplication SRG; FedRAMP SaaS where applicableVisibility & AnalyticsAU-6/SI-4/IR-4, NIST CSF Detect, GDPR Art.32, PCI 10/11
Cisco Enterprise Infrastructure reference — companion to cisco-enterprise-infrastructure-reference.md / .docx. Vanta 38-framework catalog used as the compliance map; DoD ZT Strategy pillars used for ZTA alignment. August 2026.