1. Zoned architecture map
Untrust — Internet / Cisco cloud
Meraki DashboardCloud control plane for MR / CW-M; FedRAMP Moderate (Gov)
Cisco SpacesLocation, IoT, OpenRoaming, AFC proxy
CSSM / Smart LicensingSLUP reporting (or CSSM On-Prem in air gap)
Umbrella · ThousandEyes · Catalyst Center CloudDNS security, path tests, cloud monitoring
AFC service6 GHz standard-power authorization
DMZ — exposed services
Guest Anchor 9800-CLMobility tunnel terminus for guest traffic
ISE PSN (guest)CWA / sponsor portal, OWE guest SSID
Spaces Connector VMOutbound-only bridge to Spaces
Reverse proxy (F5 / NGINX)Portal front end, RADIUS VIP option
Edge firewall (PA / FTD)Zone policy, egress allow-lists
Trust — control, identity, management, clients
Catalyst 9800 HA SSO pairActive/standby over RP+RMI; CAPWAP DTLS; tags & profiles; RRM leader
N+1 9800 (site B)Primary/secondary/tertiary AP failover
EWC on AP / 9800-SWSmall-site and SD-Access embedded controller
ISE PAN / MnT / PSN802.1X EAP-TLS, MAB, iPSK, posture, TrustSec SGT, TACACS+
AD / PKI (CA, OCSP)Device+user certs (P-384 for CNSA), RADIUS cert, WLC cert
DNS · DHCP opt43 · NTPAP discovery and time source
Catalyst CenterAssurance, SD-Access, SWIM, aWIPS/rogue, Intelligent Capture, AI-RRM
SIEM (Elastic / Wazuh)STIG audit, NetFlow/AVC, telemetry
Automation (Ansible / NetBox)STIG checks, backups, config drift
Catalyst 9K access switches802.3bt PoE, mGig, AP dot1x, SGT inline
Catalyst 9100 / CW917x APsLocal · Flex · Fabric · Mesh · Monitor · Sensor · WGB
Industrial IW916x (URWB)Vehicles, cranes, rail; <10 ms handoff
2. Stack view — who sits on whom
Experience Corp · Voice · IoT · Guest SSIDs → VLAN / SGT / QoS via AAA override
Services AVC/NBAR2 · QoS/Fastlane · mDNS gateway · Umbrella · EoGRE · Multicast · Telemetry
Security WPA3-Ent 192-bit · EAP-TLS · PMF · OWE · iPSK/MAB · aWIPS · Rogue · CAPWAP data DTLS · FIPS mode
Mobility Mobility groups · Anchor/Foreign · 802.11r/k/v · OKC · Fast roaming
RF RRM (DCA · TPC · CHD · FRA) · CleanAir · RF profiles · AI-Enhanced RRM · Wi-Fi 6/6E/7 (OFDMA, MLO, 320 MHz, AFC)
Control plane 9800 (appliance / -CL / cloud) · EWC · Meraki cloud · CAPWAP · Tags (policy / site / RF)
Identity & PKI ISE · AD/LDAP · CA/OCSP · TACACS+ · pxGrid
Infrastructure Catalyst 9K PoE/mGig · DHCP/DNS/NTP · Firewalls · Hypervisor for -CL/ISE/Catalyst Center
3. Client onboarding flow
AP boots→
DHCP opt 43 / DNS→
CAPWAP discovery→
DTLS (AP cert ↔ WLC cert)→
Join + tags + image→
RUN
Client assoc→
802.1X EAPOL→
WLC → RADIUS → ISE→
AD/LDAP + OCSP→
Accept + VLAN/SGT/dACL→
4-way + PMF→
DHCP → posture/CoA → data
4. HA layers
Controller HA SSO (Active ==RP/RMI== Standby, sub-second, ISSU, rolling AP upgrade) Site N+1 (APs: primary / secondary / tertiary controller) AAA ISE PSN pair + VIP + Flex local EAP / RADIUS fallback Data path FlexConnect local switching survives WAN loss RF Overlap design + CHD; dual PSU / dual closet switches (802.3bt) Management Catalyst Center 3-node; ISE PAN failover; Spaces Connector pair Certificates OCSP/CRL redundancy + expiry monitoring (most common real outage)
5. Deployment-mode decision
| Need | Mode | Data plane | Control |
|---|---|---|---|
| Campus, L3 roaming | Local | CAPWAP tunnel to WLC | 9800 |
| Branch must survive WAN loss | FlexConnect | Local switching at AP | 9800 (standalone fallback) |
| SGT to the edge, SD-Access | Fabric | VXLAN to fabric edge | 9800 + Catalyst Center |
| No cabling | Mesh / Flex+Bridge | AWPP wireless backhaul | 9800 |
| Small site, no WLC | EWC | Local | AP itself |
| SaaS-first, distributed | Meraki | Local bridge | Meraki cloud |
| Vehicles / rail / cranes | URWB | MPLS-over-wireless | IoT Ops Dashboard |
6. Lab tiers & compliance at a glance
Tier 1 — Bare minimum 3 VMs + 1 AP
- 9800-CL small
- ISE single node
- RHEL services (DNS/DHCP/NTP/CA/syslog)
- 1× C9100 AP on PoE switch
Tier 2 — Every role once 12 VMs + 2 APs
- + Guest anchor 9800-CL & ISE PSN in DMZ
- + Catalyst Center VA, AD/PKI, SIEM, automation
- + Spaces Connector, reverse proxy, cloud sim
Tier 3 — Pragmatic HA (worth it) 14 VMs
- + 2nd 9800-CL → HA SSO (RP+RMI)
- + 2nd ISE PSN behind VIP
- N+1 practiced via anchor as tertiary
Tier 4 — Full HA (costs learning) 22+ VMs
- Anchor SSO pair, ISE 4+2 nodes
- Catalyst Center 3-node (~96 vCPU / 768 GB)
- Do this on dCloud or customer gear
OSS equivalents
- OpenWISP + OpenWrt/hostapd ≈ 9800 + APs
- FreeRADIUS + PacketFence + Keycloak ≈ ISE
- LibreNMS/Zabbix + Grafana + Kismet ≈ Catalyst Center + aWIPS
- FreeIPA + step-ca ≈ AD/PKI · Wazuh/Elastic ≈ SIEM · OPNsense ≈ PA zones
Compliance anchors
- DISA WLC SRG + IOS-XE NDM/RTR STIGs, WLAN AP/Client/Bridge STIGs, DoDI 8420.01
- FIPS 140-3 mode; WPA3-Ent 192-bit = CNSA 1.0 (P-384/SHA-384/GCMP-256)
- NSA CSfC Campus WLAN CP (inner WPA3 + outer IPsec)
- ZTA (800-207): EAP-TLS device+user, AP dot1x, SGT, CoA
- 800-53 AC-18/IA-3/SC-8/AU · 800-171 3.1.16-17 · CMMC L2
- Vanta map: SOC 2, ISO 27001/17/18/701, CJIS 5.5.7, HIPAA/HITRUST, PCI 4.0 (1.3.3, 11.2), GDPR/APPI, NIS 2/DORA, ISO 42001/EU AI Act (AI-RRM governance)