Free CCNA | Software-Defined Networking | Day 62 | CCNA 200-301 Complete Course — Transcript
Full transcript
- 0:01Welcome to Jeremy’s IT Lab.
- 0:03This is a free, complete course for the CCNA.
- 0:06If you like these videos, please subscribe to follow along with the series.
- 0:10Also, please like and leave a comment, and share the video to help spread this free series
- 0:14of videos.
- 0:15Thanks for your help.
- 0:17In this video we will look at software-defined networking.
- 0:21In the first video of this network automation series we already covered the fundamentals
- 0:25such as centralizing the control plane in an SDN controller, northbound and southbound
- 0:30APIs, etc.
- 0:32So, in this video we’ll take a more in-depth look at one of Cisco’s SDN offerings, SD-Access,
- 0:39Software-Defined Access.
- 0:40We’ll cover exam topics 6.3 and 6.4.
- 0:44You’ll learn new terms like overlay, underlay, and fabric which are essential concepts in
- 0:49SDN that we haven’t covered yet.
- 0:52Here’s what we’ll cover in this video.
- 0:56First I’ll briefly review the points about SDN that you’ll need to remember for this
- 0:59video.
- 1:01Then I’ll introduce Cisco’s SD-Access, including important concepts like underlay,
- 1:05overlay, and fabric.
- 1:07I’ll also introduce Cisco’s DNA Center management platform, which is an essential
- 1:12part of SD-Access, and compare it to traditional network management.
- 1:18Make sure to watch until the end of the video for a bonus practice question from Boson Software’s
- 1:23ExSim, the best practice exams for the CCNA.
- 1:26Let’s reviews some points about SDN.
- 1:31SDN is an approach to networking that centralizes the control plane into an application called
- 1:36a controller.
- 1:38Traditional control planes use a distributed architecture, which means that every network
- 1:42device has its own control plane.
- 1:44The control planes of each network device use protocols like OSPF to communicate with
- 1:49each other and share routing information, each device has its own ACLs and security
- 1:54rules, etc.
- 1:55That’s a distributed control plane.
- 1:58An SDN controller centralizes control plane functions like calculating routes.
- 2:03Network devices no longer use OSPF to share information with each other, instead they
- 2:08share information with the controller, which takes that information and calculates routes
- 2:12for the entire network.
- 2:14Now, depending on the SDN solution the entire control plane might be centralized in the
- 2:19SDN controller, or perhaps only part of the control plane is centralized, leaving some
- 2:24functions on the individual network devices.
- 2:29The controller can interact programmatically with the network devices using APIs.
- 2:34Specifically it uses what we call the southbound interface to do that.
- 2:39Then there is also the northbound interface, which is what allows us to interact with the
- 2:43controller using our scripts and applications.
- 2:45Okay, those are the fundamental points of SDN that I wanted to review.
- 2:52And here’s one more look at the SDN architecture we covered in the first video of this automation
- 2:57section.
- 2:58The applications are on top, the controller in the middle, and the network devices on
- 3:02the bottom.
- 3:03Actually, these three ‘layers’ of the architecture have names.
- 3:07On top there is the application layer.
- 3:10This layer contains scripts and applications that tell the SDN controller what network
- 3:14behaviors are desired.
- 3:16Note that this isn’t the application layer of the OSI model, this is a totally different
- 3:21concept.
- 3:22We’re not talking about the OSI model here.
- 3:24Anyway, next is the control layer.
- 3:27This contains the SDN controller that receives and processes instructions from the application
- 3:31layer.
- 3:32Although this is a separate concept from the ‘control plane’, this layer is also what
- 3:37contains the centralized control plane of the network.
- 3:41And finally there is the infrastructure layer, which contains the actual devices that are
- 3:44responsible for forwarding messages across the network.
- 3:48I didn’t mention these layers in earlier videos, so take the time to learn them now.
- 3:53The application layer contains apps and scripts for instructing the SDN controller, the control
- 3:58layer contains the SDN controller, and the infrastructure layer contains the network
- 4:03devices.
- 4:04Okay, so I’ve told you the basics of what SDN is and its purpose, but we still haven’t
- 4:09looked at a specific example of SDN.
- 4:12So, let’s take a look at one, Cisco Software-Defined Access.
- 4:19Cisco SD-Access is Cisco’s SDN solution for automating campus LANs.
- 4:23So, office wired and wireless LANs, for example.
- 4:28Cisco has other SDN solutions, for example ACI, Application Centric Infrastructure, is
- 4:33their SDN solution for automating data center networks.
- 4:37Remember when I explained spine-leaf architecture earlier in the course?
- 4:41That is used extensively in ACI data center networks.
- 4:46Cisco also has SD-WAN, their SDN solution for automating WANs.
- 4:50But for now let’s look at SD-Access.
- 4:54Cisco DNA, Digital Network Architecture, Center is the controller at the center of SD-Access.
- 5:01In the previous video about REST APIs we sent a REST API call to DNA Center, so perhaps
- 5:07you remember that name.
- 5:08Okay, let’s look at the basic SD-Access architecture.
- 5:12At the center, in the control layer, we have DNA Center.
- 5:16And then under it we have the network devices in our campus LAN in the infrastructure layer.
- 5:21These devices form the fabric of SD-Access, and I’ll explain that term in the next slide.
- 5:27In the application layer we have our scripts and apps that interact with DNA center.
- 5:33These could be tools we develop, third-party tools, or tools directly from Cisco.
- 5:38DNA Center itself also has a GUI that we can use to control it.
- 5:43Okay, so that’s the basic architecture of Cisco’s SD Access.
- 5:48Notice how it fits perfectly into the SDN Application layer, Control layer, Infrastructure
- 5:53layer model.
- 5:54Next let’s look at that term ‘fabric’.
- 5:57To understand the fabric, you need to understand two other terms.
- 6:01First, the underlay is the underlying physical network of devices and connections, wired
- 6:07and wireless, which provide IP connectivity, for example with a routing protocol like IS-IS.
- 6:14Usually I’d use OSPF as an example, since it’s the most common interior gateway routing
- 6:18protocol, but soon you’ll see why I chose IS-IS for this example.
- 6:24Basically the underlay is a bunch of multilayer switches and their connections.
- 6:29Then the overlay is the virtual network built on top of the physical underlay network.
- 6:34For example, SD-Access uses a protocol called VXLAN, virtual extensible LAN, to build tunnels.
- 6:41And fabric is the term we use to refer to the combination of the overlay and underlay,
- 6:47the physical and virtual network as a whole.
- 6:50For example, this is the underlay network.
- 6:53The physical multilayer switches and their connections form the underlay, and they are
- 6:57perhaps running IS-IS to share routing information and provide connectivity throughout the network.
- 7:04Then the overlay network consists of VXLAN tunnels, for example between these two switches.
- 7:11When hosts in the LAN communicate with each other, their traffic is sent over the VXLAN
- 7:15tunnels.
- 7:16That’s the overlay network.
- 7:19And the fabric refers to the physical and virtual network as a whole, overlay plus underlay.
- 7:24Both are necessary to make SD-Access work.
- 7:27Okay, now let me give a little more detail about both the underlay and overlay.
- 7:32So, let’s talk about the underlay.
- 7:36The underlay’s purpose is to support the VXLAN tunnels of the overlay.
- 7:40To make a virtual network of tunnels, the devices first need to be connected and able
- 7:44to reach other of course, so the underlay is very important.
- 7:49There are three different roles for switches in SD-Access.
- 7:53Those are edge node, these are switches that connect to end hosts, like a traditional access
- 7:58layer switch.
- 7:59Then there are border nodes, which connect to devices outside of the SD-Access domain,
- 8:05for example connecting to a WAN router.
- 8:08And finally there are control nodes, which use a protocol called LISP, Locator ID Separation
- 8:14Protocol, to perform various control plane functions.
- 8:17I think LISP is far beyond what you need to know for the CCNA, so just know that it is
- 8:22used for the control plane of SD-Access.
- 8:26Note that you can add SD-Access on top of an existing network if your network hardware
- 8:30and software supports it.
- 8:33This is called a brownfield deployment, when you add it on to an already existing network.
- 8:39If you’re curious which hardware supports it, you can google ‘Cisco SD-Access compatibility
- 8:44matrix’, but you don’t have to know the specific devices for the CCNA.
- 8:49And also note that in this case DNA center won’t configure the underlay, because this
- 8:54could be a major risk to the current working production network.
- 8:59Ideally you will be using a greenfield deployment, which is a totally new network built for the
- 9:03purpose of SD-Access.
- 9:06In this case DNA center will configure the devices for the optimal SD-access underlay.
- 9:12For example, all switches are layer 3 and use IS-IS as their routing protocol.
- 9:17That’s why I mentioned IS-IS in the example earlier.
- 9:20Additionally all links between switches are routed ports, so STP is not needed to avoid
- 9:26Layer 2 loops.
- 9:28And edge nodes, so access switches, act as the default gateway of end hosts.
- 9:33This is known as a routed access layer, we’ve brought layer 3 all the way down to the access
- 9:38switches that end hosts connect to.
- 9:41Let me demonstrate with a diagram.
- 9:44Here’s a traditional LAN.
- 9:46Notice that STP is used to avoid layer 2 loops, and an FHRP, for example HSRP, is used by
- 9:53the distribution layer switches to provide a redundant default gateway for the end hosts.
- 9:58So, to send traffic out of their local network, they will send it to the virtual IP provided
- 10:03by the FHRP, 192.168.1.1.
- 10:09In an SD-access underlay, however, all connections between switches are Layer 3 and IS-IS is
- 10:14used to exchange routing information.
- 10:17Note that STP is no longer needed, and an FHRP isn’t needed either.
- 10:22Instead, the access layer switches are the default gateways of the end hosts.
- 10:27Now we have a routed access layer.
- 10:31Now let me briefly introduce a few aspects of the SD-Access overlay.
- 10:36First, LISP provides the control plane of SD-Access.
- 10:39A list of mappings of EIDs to RLOCs is kept.
- 10:44Let me explain those terms.
- 10:46EIDs, endpoint identifiers, identify end hosts connected to edge switches, and RLOCs, routing
- 10:53locators, identify the edge switch which can be used to reach the end host.
- 10:58Of course, there is a lot more detail to cover about LISP, but I think with just that you
- 11:02can see how it differs from the traditional control plane.
- 11:05Instead of a traditional routing table to locate destination hosts, a DNS-like system
- 11:10of mappings is used.
- 11:13Cisco TrustSec, CTS, provides policy control such as QoS and security policy.
- 11:20Just remember that name, Cisco TrustSec, you don’t have to know about its functionality.
- 11:25And finally VXLAN provides the data plane of SD-Access, the tunnels that are used to
- 11:30actually forward traffic in the data plane.
- 11:33Let’s look at how VXLAN tunnels work with LISP.
- 11:37Notice that SW3 is a control node, so it is important for the function of LISP.
- 11:43PC2 is connected to SW2, and it tells the control node that PC2 is reachable via SW2.
- 11:49So, SW3 creates that mapping.
- 11:53Now PC1 wants to send traffic to PC2, so it sends it to the default gateway, SW1.
- 11:58SW1 asks SW3, how can I reach PC2?
- 12:02And SW3 informs it that PC2 is reachable via SW2.
- 12:06So, the message from PC1 is forwarded over a VXLAN tunnel between SW1 and SW2.
- 12:12Okay, that’s all I’ll say about the overlay for now.
- 12:15VXLAN does more than just create tunnels, it provides a lot of features to SD-Access
- 12:20which I won’t get into in this video.
- 12:23Just know the difference between fabric, overlay, and underlay, and know some basics of SD-Access
- 12:28like edge node, border node, and control node, LISP, VXLAN, and Cisco TrustSec.
- 12:36Now let’s look a bit more at DNA Center.
- 12:39DNA Center itself has two main roles.
- 12:42First, it is the SDN controller used in SD-Access, as I mentioned earlier.
- 12:48Additionally it can be a network manager in a traditional network that isn’t using SD-Access.
- 12:53In that case, although it doesn’t provide SD-Access functions, it still acts as a central
- 12:58point to monitor, analyze, and configure the network.
- 13:02Although I will mention both purposes, for this lecture we’re focusing on the SD-Access
- 13:07application.
- 13:08Note that DNA Center is a software application installed on Cisco UCS server hardware.
- 13:14I mentioned Cisco UCS in the virtualization lecture of this course.
- 13:19DNA Center has a REST API, as you already know, which can be used to interact with it.
- 13:25And its southbound interface supports protocols such as NETCONF and RESTCONF, as well as traditional
- 13:31protocols Telnet, SSH, and SNMP to control and monitor devices.
- 13:37DNA Center enables something called intent-based networking, IBN, yet another buzzword.
- 13:44Basically, the goal is to allow the engineer to communicate their intent for network behavior
- 13:49to DNA Center, and then DNA Center will take care of the details of the actual configurations
- 13:54and policies on the devices.
- 13:57It simplifies the process, and allows engineers to spend time on more important things than
- 14:01analyzing and configuring policies on devices one at a time.
- 14:05Here’s one example.
- 14:07Traditional security policies using ACLs can become very cumbersome.
- 14:11For example, ACLs can have thousands of entries, and the intent of entries is easily forgotten
- 14:16with time and as engineers leave and new engineers take over.
- 14:21Looking at another engineer’s configurations and trying to figure out the intent is often
- 14:25not an easy task.
- 14:27And configuring and applying ACLs correctly across a network is cumbersome and leaves
- 14:31room for error.
- 14:32DNA Center, on the other hand, allows the engineer to specify the intent of the policy,
- 14:38for example this group of users can’t communicate with this group, or this group can access
- 14:43this server but not that server, etc, and DNA Center will take care of the exact details
- 14:48of implementing the policy.
- 14:51This is what configuring policies on DNA Center looks like.
- 14:55Notice on the left here we have source groups.
- 14:57Of course, you’d have to define the groups first, which users belong in which groups.
- 15:02And here we have those same groups as destination.
- 15:05Up here we have the legend for the colors in the policy grid.
- 15:09Note that the entire grid is white now, so default.
- 15:12However, let’s say any traffic sourced from users in the developers group and destined
- 15:17for the Test_Servers group should be permitted.
- 15:20Now, what about traffic sourced from the guest group?
- 15:23They shouldn’t be able to access our servers, so we’ll make that red.
- 15:28How about users in the employees group?
- 15:30Maybe that depends on various factors, we can’t just permit or deny all traffic, so
- 15:35we would want to make a custom policy for that.
- 15:39We can go ahead and define policies like this, it’s a very simple and straightforward way
- 15:43of creating and applying policies across the entire SD-Access fabric.
- 15:48No need to configure policies on devices one at a time.
- 15:51I’m not showing the whole process here of course, but one thing to note is that the
- 15:55engineer can write an explanation for each policy made, making it much easier to understand
- 15:59the purpose of policies later.
- 16:01Okay, now let’s take a look at some of the other features of DNA Center.
- 16:07In the menu on the left side you can see there are various sections, and I’ve opened the
- 16:11design section.
- 16:13Here we can build the network hierarchy, manage IP addresses and subnets, configure DHCP servers,
- 16:19DNS servers, etc, among other things.
- 16:22Here, for example, I’m looking at one site, SJC-20, on a map.
- 16:28You can map your enterprise’s sites all over the world and create hierarchies based
- 16:31on country, etc.
- 16:35In the policy menu you can configure policies like the example I showed you earlier.
- 16:39You tell DNA Center how the network devices should behave, and DNA Center will change
- 16:43that into configurations on the devices in the network.
- 16:47For example, here’s that group-based access control page again.
- 16:50A simple and logical way to configure network policies.
- 16:54In the provision menu we can manage our device inventory and add new devices.
- 16:59Other services are available as well, as you can see in the menu.
- 17:03Here’s the inventory page.
- 17:06In the side bar you can see that there are 3 unassigned devices under global.
- 17:10By default, when you add devices to DNA Center they will be under the global site, until
- 17:15you assign them to a specific site.
- 17:18You can see their status of ‘managed’ here, this means they are under control of
- 17:22DNA Center, they are not independent devices.
- 17:25This is also the default setting when you register a device in DNA Center.
- 17:29Here you can see the compliance status of the devices.
- 17:32The top device is compliant with our policies, but the bottom two aren’t.
- 17:37I clicked on one of the non-compliant devices, and you can see why it is labeled as non-compliant.
- 17:43The software image, the version of IOS, is not up to date.
- 17:48The version should be 17.03.03, but currently it is 16.11.1c.
- 17:54We can use DNA Center to update that later if we want.
- 17:57And here you can see that it is also non-compliant with some security advisories.
- 18:03Anyway moving on, in the assurance section of the menu you can monitor the status of
- 18:07the network.
- 18:08You can make sure the devices are all up and running without issues.
- 18:12For example, here I can see which devices in the network are considered ‘healthy’
- 18:16by DNA Center.
- 18:183 of 4 devices are in good health, and 1 of them simply has no health data.
- 18:22Okay, that’s all we’ll look at for now, but if you want to look around DNA Center
- 18:26yourself you can check out the DevNet sandbox at sandboxdnac.cisco.com, and you can see
- 18:33the username and password here.
- 18:35I highly recommend checking it out and looking around at what DNA Center has to offer.
- 18:40Okay, that was a quick look at DNA Center, but to be honest you don’t have to be familiar
- 18:46with all of the functions of DNA Center for the CCNA.
- 18:49Basically, just understand its role as a network controller in SD-Access architecture, and
- 18:54also understand that it can be a network management platform in a traditional network.
- 18:59However, the exam topics do state that you should be able to compare DNA Center-enabled
- 19:04device management with traditional device management.
- 19:07Actually, I’ve covered most of these points already when I first introduced network automation,
- 19:13but let’s review to make sure.
- 19:14First, let’s review some characteristics of traditional network management.
- 19:19Devices are configured one-by-one via SSH or console connection.
- 19:23This is what we’ve been doing throughout the labs in this course.
- 19:27Devices are manually configured via console connection before being deployed.
- 19:31This means when deploying a new device to a network.
- 19:33You first have to manually set it up before connecting it to the network.
- 19:39Configurations and policies are managed per-device, in a distributed manner.
- 19:42There is no central management.
- 19:45New network deployments take a long time due to the manual labor required.
- 19:49Setting up dozens of new devices manually takes a lot of time, and also errors and failures
- 19:54are more likely due to increased manual effort.
- 19:57Now, I don’t want to make it seem like traditional network management is bad, but you should
- 20:01be aware of these potential downsides.
- 20:05Now some characteristics of DNA Center-based network management.
- 20:09Devices are centrally managed and monitored from the DNA Center GUI or other applications
- 20:14using its REST API.
- 20:16In this video I showed you the DNA Center GUI, but using the REST API other applications
- 20:21can be used to interact with DNA Center too.
- 20:25With DNA Center, the administrator communicates their intended network behavior to DNA Center,
- 20:31which changes those intentions into configurations on the managed network devices.
- 20:37Configurations and policies are centrally managed, they’re all stored and managed
- 20:40on DNA Center.
- 20:42Software versions are also centrally managed.
- 20:44DNA Center can monitor cloud servers for new versions and then update the managed devices
- 20:49when needed.
- 20:50In this video you saw an example of DNA Center showing us an alert for a device with an old
- 20:55software version.
- 20:57Finally, with DNA Center new network deployments are much quicker.
- 21:01New devices can automatically receive their configurations from DNA Center without manual
- 21:07configuration.
- 21:08Not only is this faster, human error is reduced too, which is a huge bonus.
- 21:12Okay, that’s all I’ll say about this.
- 21:16Most of these points we have already covered, but make sure you’re aware of them because
- 21:19it is mentioned on the exam topics.
- 21:21Okay, let’s review what we covered.
- 21:24We first reviewed SDN, and I newly introduced the terms application layer, control layer,
- 21:29and infrastructure layer.
- 21:31Then, as an example of SDN, I introduced some concepts of Cisco SD-Access.
- 21:37The main takeaways from this section are the concepts of underlay, overlay, and fabric.
- 21:41Make sure you understand those concepts.
- 21:44Then I showed you some functions of Cisco DNA Center, and compared network management
- 21:48with DNA Center to traditional network management.
- 21:52Remember, DNA Center is an SDN controller in SD-Access architecture, but it can also
- 21:57be used as a general network management tool even in networks that don’t use SD-Access.
- 22:03Make sure to watch until the end of the quiz for a bonus practice question from Boson Software’s
- 22:07ExSim, the best practice exams for the CCNA.
- 22:10Okay, let’s go to quiz question 1.
- 22:14Which of the following terms describes the network of devices and physical connections?
- 22:20Pause the video now to select the best answer.
- 22:24Okay, the answer is A, underlay.
- 22:29The underlay refers to the underlying physical network, and then the virtual overlay network
- 22:33is built on top of it.
- 22:35The combination of underlay and overlay is called the fabric.
- 22:38Okay, let’s go to question 2.
- 22:42In which of the following layers would you expect to find scripts that interact with
- 22:46the controller?
- 22:47Pause the video now to select the best answer.
- 22:52Okay, the answer is B, application.
- 22:57In SDN architecture, the application layer includes apps and scripts that can be used
- 23:01to interact with the controller, which is in the control layer.
- 23:05Finally the bottom layer is the infrastructure layer, which includes the network devices.
- 23:09Okay, let’s go to question 3.
- 23:14Which of the following is a characteristic of an optimal SD-Access underlay network as
- 23:18configured by DNA-Center?
- 23:20Pause the video now to select the best answer.
- 23:25Okay, the answer is B, all links between switches are layer 3.
- 23:31This means that spanning tree is not needed, and no links will have to be disabled because
- 23:35there is no risk of layer 2 loops.
- 23:37Okay, let’s go to question 4.
- 23:41Which protocol is used to create virtual tunnels in the SD-Access overlay?
- 23:46Pause the video now to select the best answer.
- 23:50Okay, the answer is D, VXLAN.
- 23:55It is used to create virtual tunnels in the overlay network.
- 23:59And although we didn’t cover any details at all, the ‘extensible’ in the name ‘virtual
- 24:03extensible LAN’ is very important.
- 24:06It means that VXLAN supports many different features which are used by SD-Access.
- 24:10Okay, let’s go to question 5.
- 24:15Which of the following are valid switch roles in Cisco SD-Access?
- 24:18(select three) Pause the video now to select the best answers.
- 24:24Okay, the answers areA, C, and D. Control, border, and edge nodes.
- 24:32These are the three different switch roles in Cisco SD-Access, and there is no such thing
- 24:36as a management node.
- 24:37Okay, that’s all for the quiz.
- 24:40Now let’s take a look at a bonus question in Boson Software’s ExSim for CCNA.
About this transcript
This page contains the full transcript of Free CCNA | Software-Defined Networking | Day 62 | CCNA 200-301 Complete Course by Jeremy's IT Lab, generated from the public captions YouTube serves with the video. The transcript has 3,870 words across 361 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.