- 11
- 31 147
Pablo M
เข้าร่วมเมื่อ 20 ก.ย. 2022
Cisco DNA Center - Import/Manage Certificates
Following the Cisco DNA Center Security Best Practices guide to import a certificate using OpenSSL (This guide has since been updated please refer to link below, the process remains the same with some changes on the certificate alt names section).
www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html#id_90320
If you have any questions feel free to drop them in the comment section below.
www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html#id_90320
If you have any questions feel free to drop them in the comment section below.
มุมมอง: 1 890
วีดีโอ
Software Defined Access Multi-site SD-A Transit Pub/Sub in Cisco DNA Center
มุมมอง 2.2K2 ปีที่แล้ว
In this video I'll be demoing how to build multi-site using SD-Access transit with LISP Pub/Sub in Cisco DNA Center. Site 2 will be a FiaB (Fabric in a box). If you have any questions feel free to drop them in the comment section.
Cisco DNA Center - A Taste of APIs
มุมมอง 1.1K2 ปีที่แล้ว
Join me in this video where I'll be giving you a taste of APIs to quickly deploy the network hierarchy and network settings and save you a lot of clicks in the GUI. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
Software Defined Access Fabric Guest wired / wireless in Cisco DNA Center
มุมมอง 1.5K2 ปีที่แล้ว
In this video I'll be demoing how to provision a Guest VN in SD-Access for both wired & wireless clients in Cisco DNA Center. Wired clients will be MAB authenticated into the Guest VN and wireless clients will go through a self registration guest portal. If you have any questions feel free to drop them in the comment section below.
Software Defined Access wireless Fabric provision in Cisco DNA Center
มุมมอง 2.1K2 ปีที่แล้ว
In this video I'll be demoing how to provision an SD-Access wireless fabric in Cisco DNA Center. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
Software Defined Access Fabric, provisioning a subnet for VoIP phones in Cisco DNA Center
มุมมอง 4592 ปีที่แล้ว
This is a follow up video of my previous video "Software Defined Access switching Fabric provision in Cisco DNA Center" where I'll be demoing how to add the voice subnet on an SD-Access fabric in Cisco DNA Center. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
Software Defined Access switching Fabric provision in Cisco DNA Center
มุมมอง 1.1K2 ปีที่แล้ว
In this video I'll be demoing how to provision an SD-Access switching fabric in Cisco DNA Center. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
LAN Automation for Software Defined Access in Cisco DNA Center
มุมมอง 2.8K2 ปีที่แล้ว
In this video I'll be demoing the LAN Automation feature in Cisco DNA Center. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
C9800 WLC and AP Onboarding using Plug and Play (PnP) with Cisco DNA Center
มุมมอง 10K2 ปีที่แล้ว
In this video I'll be demoing the Plug-and-Play (PnP) feature in Cisco DNA Center for WLC 9800 and APs. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
Software Image Management (SWIM) with Cisco DNA Center
มุมมอง 2K2 ปีที่แล้ว
In this video I'll be demoing the Software Image Management (SWIM) feature in Cisco DNA Center. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn.
Network Device Onboarding (switching C9300) using Plug and Play (PnP) with Cisco DNA Center
มุมมอง 6K2 ปีที่แล้ว
In this video I'll be demoing the Plug-and-Play (PnP) feature in Cisco DNA Center for switching. If you have any questions feel free to drop them in the comment section or reach out directly to me in LinkedIn. Apologies I had misconfigured the screen recording tool and I cropped too much of the top and bottom parts of the screen. The content can still be seen however, some buttons I'm clicking ...
Very nice
What is you provisioned the APs on the WLC 9800 directly. How do you Add them into DNAC(CCC)? Or/ and get the WLC to talk to DNAC? And can you in future manage them through DNAC to push policies down to the WLC?
Thanks Pablo
Hi Pablo, Do you know if there is cisco dcloud or any other resource available to try out Lab scenario?
Hi, dCloud is accessible to all Cisco partners. You have multiple demos, both instant and scripted labs you can schedule and configure. Search for SD-Access or Catalyst Center (DNA Center) in dCloud catalog.
Hi Pablo, is it mandatory to create a separate Guest VN? Can I use existing Campus VN and just use a separate pool for Guest inside it
In this series, I used the Dedicated Guest VN. It uses the same B/CP as the other VNs. By ticking the box for Guest VN, Catalyst Center recognizes it. When you want to add a Guest SSID or a captive portal, Catalyst Center will know it is for guests and give you the subnet from the Guest VN pool when enabling it. So, it makes it easier.
Thanks for the great video detailing the integration of WLC to DNAC / SDA. question: Let assume I don't have SD-access but i would like to use DNA for my switch provisioning; can I also do the integration of WLC to my DNA to manage the provisioning of my WAPs, again without SD-Access implemented? Any guide or video about that?
Hi, this was supported in the past, but it has been discontinued. Embedded WLC on a C9k switch is only supported on an SD-Access deployment at present. See guide: www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-744299.html
@@pabmart Thanks for sharing this Doc. But this doc talks about Embedded WLC in Catalyst 9000 = Some Catalyst 9K have built-in WLC right? But that is not what I am talking about: I just want to use DNA Center to manage the deployment and provisioning of my WLC and WAPs. I don't want to use the WLC to provision my WAPs, but rather integrate my WLC into DNA and use DNA to provision my WAPs. Of course my environment doesn't have SD-Access, and i am already using DNA to provision my IOS-XE switches (non SD-access environment), just trying add my physical C9800 in this environment but manage my WAPs from DNA and not from the WLC....hope I am not confusing you by being too repetitive. In Sum, I want to do what this video is doing but in a non-SD-Access environment
@@mariejosv Apologies if I misunderstood. Yes, you can do that and it's a typical use-case. Once you add your WLC to the inventory via a discovery, Catalyst Center will discover the APs attached to said WLC. You can then manage the WLC from there and the best of all, get all the assurance capabilities in Catalyst Center. Hope that helps.
@@pabmart Thanks a lot. I feel confident now moving in that direction. Last question: What are the Assurance features that DNA has over the WAPs or over the WLC itself that the WLC cannot provide? what are the real added values using the DNA vs relying on the WLC?
so why the APs did not show up under PnP page but straight to inventory?
Catalyst Center discovers the AP via the WLC and shows up directly in inventory.
Hi @Pablo, why did you clear the port assignment for Te1/0/37 connecting to the APs to match the expected configuration of Te1/0/38 when comparing the 'show running-config'? th-cam.com/video/qUzTsNuhU0c/w-d-xo.html
I recorded these videos ~2Ys ago, I can't remember exactly. But after looking through it again, it seems that Catalyst Center for some reason left that port behind and I did a manual assignment to then force the normal port configuration which should have been the same as 1/0/38. Maybe not the answer you were expecting, but hope that helps.
Thanks Pablo for this awesome and very useful video series on SD-Access. Helped me a lot to learn about SD-Access. I though have a question, why did you used extended VLANs (3001, 3002, so on and so forth) in L3-Hand-off configurations for VNs. Would appreciate your response.
Glad it helped. Not much thought went into it. Essentially earlier versions of Catalyst Center hard coded those VLANs while automating the L3 handoff starting at 3001. In this version of the lab CC allows the user to manually enter the VLAN ID. As all my templates and notes were already done with 3001-300x from previous labs, I just continued using those.
@@pabmart Got it. Thank You very much.
Nice work! Have you tried using the DNS Discovery method with the PnP agent, and if so, do you have any insights on the best way to set it up please?
Hi, yes I've tried that and works fine. I just prefer the option 43 as it's quick and easy. For DNS you have to include the domain in your DHCP offer. The device will then look for PNPSERVER.domain.com, you can see more in the user guide: www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-7/user_guide/b_cisco_dna_center_ug_2_3_7/m_onboard-and-provision-devices-with-plug-and-play.html#id_90879
Great work sir. Thank you.
Hello Pablo, love your videos ! Can I ask if you are using any lab tools like gns3 to do these videos ? I would like to practice dna center + ise but im not sure where to look for. Thanks in advance !
For this lab, most of the equipment was physical. The only VM I think was the C9800 WLC and the Linux machine.
Thank you for your quick answer ! Do you know if there is any way of having a DNA center + ISE evaluation license for practice purposes ? @@pabmart
@@niichinonii559 If you get your hands onto an ISE image, it will give you 90days evaluation license. For Catalyst Center you'll need either the physical appliance, or get the ISO to put on ESXi or AWS. No license required.
Hi Pablo How APs are discovered in Inventory in DNAC?
APs attach to the WLC. Catalyst Center (formerly DNAC) discovers the WLC. CC then learns the APs via the WLC and adds to inventory.
Very nice video!!!
Sound is not clear. if you can improve it will be good
Sounds is clear on my side. Please check your headset or audio output. Thanks.
ok thanks @@pabmart
Hi Pablo very informative video, can you also upload the templete configuration just for the referece thanks
Hi, glad to hear. The template is adapted to my lab environment, there is nothing exceptional in it. Some of the things I've put: username/pass/secret (so DNAC can use that once provisioned), enable ip routing, hostname, ssh v2, some vlans, enable netconf, loopbacks and L3/L2/Trunk physical interfaces, a static route, line console, line vty. That's pretty much it. It's just the very basic setup to allow DNAC to reach, and take over it via GUI.
Pablo this is excellent and well explained video. Thanks for sharing.
Glad it was helpful!
@@pabmart I haven't tried it yet but I hope I will get this scenario soon. I have L3 SVI for vlan 10 on my router and expect switch to get connected with it using a routed interface (no vlan on switch, just like a P2P configuration). Will this dhcp part work with this scenario ?
@@vaibhavbhosle6511 You will need VLAN 1 subinterface on the upstream router and provide the DHCP on that vlan. PNP Agent works on VLAN 1 by default. You can remove VLAN 1 once PNP has finished and your device has been fully provisioned with desired config.
@@pabmart Can this PnP method be used for deploying Fabric edge switches as well ? What about smart licensing will there be any issue if choose deploying using PnP instead of LAN Automation
Thnx@@pabmart
Where did you configure the DHCP server in the topology diagram?
At the Fusion device.
@@pabmart when you do a Pnp service restart in pnp agents, it will automatically do the discovery to the fusion device? Also, don’t you have to configure the interface where the discover message goes to in DNAC?
@@estebangomez1823 Hi, no config needed in the device to be discovered. Just let it boot into out of the box state, where it runs a PNP agent. The agent will try to get an IP address and Default GW along with Option 43 via DHCP from any interface in UP status. Ideally, that will be the interface connecting upstream (to the Fusion in this case). It will use that configuration to reach out to DNAC. You have to make sure reachability is there between PNP device and DNAC (now known as Catalyst Center). Hope it helps.
Thanks Pablo
No probs!
thank you for sharing
Thanks for watching!
Any video for brownfield wlc provision
I don't have any on brownfield unfortunately. This was a from-scratch lab I did about a year ago.
Thanks for the info! Great stuff for helping me recert my CCIE. ^_^
Rock on! Glad it helped.
Thank you for this very good demonstration! I will move on and watch 1-2 other videos on your channel. It's really helpful to see SDA stuff "in action". 🙂
Glad it's helpful and yes please, if you have any questions let me know.
Hey Pablo, in that version of DNAC, where you can hardcode the IPs for the border handoff (minute 3:30) is it possible to use /31 now there as well?
Hi, Yes /31 is allowed in that field. Hope that helps.
@@pabmart yep, thanks
Hi Pablo. Could I use the same WLC (in a datacenter) to manage 2 different fabric sites(branches)? It already does in the traditional network (capwap+flexconnect)
Hi, each fabric site will require a WLC. For branch sites, you could deploy Physical, Virtual or Embedded on a C9300.
Quality of video is so poor. All fuzzy and semi-visible.
Looks fine to me on 720 & 1080 quality. Have you tried that?
Please wich routing protocol did you use between the border and the firepower
Hi, no IGP between them in this lab. I'm using static routes, and then BGP for the L3 handoff. Hope that helps.
Why is this so blurry
Hi David, maybe try adjusting the video quality feature here in TH-cam. When I play it at 480p it is fair and with 720p/1080p image is clear.
Pablo, if we have an existing brownfield controller with many SSIDs and APs can we change the controller to fabric mode and add some fabric APs without affecting the existing traditional deployment at other sites?
Hi, Yes you can have a shared WLC to manage Fabric and non-Fabric APs. Fabric is enabled per SSID not per controller. Please refer to CiscoLive session in the on-demand catalog: Fabric Fundamentals - Integrating wireless into SD-Access (Fabric Enabled Wireless) - BRKEWN-2308, for more information on this.
@@pabmart Thanks Pablo. I’ll have a look at that. It’s something customers with existing standard deployments ask as a way to keep their existing setup and migrate to SDA wireless in a staged manner on the same controllers.
Can also leave existing controllers in place, deploy new controllers in parallel, then start migrating APs on an area by area basis... So, you could have floor 1 in the new controller fabric enabled and the rest of the floors on the older controller non-fabric. Just a thought.
why newly created ssid is showing under the provision section?
When you create an SSID in Network Design, attach it to a Network Profile and assign to the site(s), it will show up in the summary of the provision workflow. It then gets provisioned to the WLC. Hope that helps.
Hello Pablo Just came to ur Channel , pls do Video how to migrate to from Legacy STP Campus Network to SDA Thanks
Hi Ali, There are a couple of great CiscoLive on-demand sessions that go over the migration to SD-Access. Take a look at BRKCRS-2812 Barcelona 2019 and TCRCRS-2500 Barcelona 2019. They are old sessions but content is still valid. Hope that helps.