cisco logo color 2020
8293  Reviews star_rate star_rate star_rate star_rate star_half

Cisco Software-Defined Access (SDA): Use Case Implementation, Operations, & Troubleshooting

This 5-day deep dive training course explores the capabilities of the Cisco Software-Defined Access (SDA) solution. Students will learn how to implement SDA for different solution verticals. It also...

Read More
$4,495 USD
Duration 5 days
Course Code SDAOTS-NTO
Available Formats Classroom, Virtual

Overview

This 5-day deep dive training course explores the capabilities of the Cisco Software-Defined Access (SDA) solution. Students will learn how to implement SDA for different solution verticals. It also addresses the details of how to operate and troubleshoot the different capabilities of the underlying solution components. Need assistance with design, installation and configuration of CatalystCenter? EnterOne can provide resources through our Professional Services team. The course qualified for 50 Cisco Continuing Education Credits (CE).

Skills Gained

Upon completing this course, the learner will be able to meet these overall objectives:

  • Articulate the value of Cisco SDA Use Cases including, for example: saving operational and management cost to maintain and support ever growing network infrastructure; central security policy to comply to regional or global regulatory requirements and enterprise security policy; deliver best-in-class services to end-users; leveraging networking insights and trends to optimize business process and workflows. Some real scenarios such as supporting multi-mode collaboration within shared workspaces in life sciences; accelerating the deployment of pop-up sites for emergency medical purposes; creating integrated building management solutions; zero-touch day 0 network turn-up of additional sites, rapid response to network threat and vulnerabilities, and similar.
  • Describe the technical capabilities of Cisco DNA Center and how they are applied in SDA Use Cases. This includes the lifecycle stages of network device discovery, assigning network devices to sites, network design options, provisioning, software image management, building a fabric, segmentation design, assurance, application policy, etc.
  • Set up an SDA environment, integrating Cisco Identity Services Engine (ISE) and other solution components as required.
  • Apply troubleshooting methods, processes, tips to resolve implementation and maintenance issues of the following aspects of the technical solution:
  • Device Onboarding, including device discovery, Plug-and-Play and LAN Automation
  • Network design settings, including sites, AAA, SNMP, Syslog, IP address pools, image management, network profiles, and authentication templates
  • Policies for access control, applications and virtual networks
  • Provisioning, including template-based provisioning for day 0 and day N operations
  • Network Segmentation, including the application of Cisco TrustSec security with Scalable Group Tags (SGTs) and Virtual Networks
  • Assurance to monitor network, endpoint, and applications to ensure best user experience
  • Integration of ServiceNow for an integrated IT service management lifecycle
  • Integration of InfoBlox for integrated IPAM

Who Can Benefit

The primary audience for this course is as follows:

  • IT management, to understand how to address key business requirements with greater efficiency and flexibility in network service delivery
  • IT solution architects, to understand the role that SDA plays in enabling such efficiency and flexibility for network services in the context of IT solution delivery
  • IT and network security architects, to understand how the integrated capabilities of the SDA solution are used to design and implement network segmentation-based security
  • IT operations engineers, integrating network and application visibility and root cause analysis into integrated IT case handling workflows
  • Networking Admin and Operations installing, integrating, configuring and operating Cisco DNA Center, Cisco Identity Services Engine (ISE), and other solution components, in the context of Cisco SDA based network services
  • Networking Field Engineers using capabilities of Cisco Catalyst Center to deploy, monitor and maintain network infrastructure for SDA based network services

Prerequisites

The knowledge and skills that the learner should have before attending this course are as follows:

  • Implementation of Enterprise LAN networks
  • Basic understanding of Enterprise switching, and wireless connectivity
  • Basic understanding of Enterprise routing connectivity
  • Basic understanding of AAA (authentication, authorization, and accounting) process and workflow
  • Programming knowledge such as Python, RestAPI is useful

Course Details

Module 1: Introduction to Ciscos Software Defined Access (SD-Access)

  • Understanding Cisco Intent-Based Networking
  • Understanding Cisco SDA Use Cases customers benefits including business and technical outcomes and capabilities
  • Cisco Catalyst Center (formerly DNAC) Introduction
  • SD-Access Overview
  • SD-Access Benefits
  • SD-Access Key Concepts
  • SD-Access Main ComponentsFabric Control Plane NodeFabric Border NodeFabric Edge NodeFabric Wireless LAN Controller and Fabric Enabled Access Points
  • Cisco Catalyst Center Automation
  • Cisco ISE (Policy)
  • Cisco StealthWatch (Traffic Analysis)
  • DNA Center Assurance

Module 2: Deployment and Initial setup for the Cisco DNA-Center

  • Cisco Catalyst Center Appliances
  • Cisco Catalyst Center Deployment ModelsSingle Node DeploymentClustered Deployment
  • Installation Procedure
  • Initial Setup and Configuration
  • GUI Navigation

Module 3: SDA - Design

  • Network design options
  • Sites
  • Creating Enterprise and Sites Hierarchy
  • Configuring General Network Settings
  • Loading maps into the GUI
  • IP Address Management
  • Software Image Management
  • Network Device Profiles
  • AAA
  • SNMP
  • Syslog
  • IP address pools
  • Image management
  • Creating Enterprise and Guest SSIDsCreating the wireless RF ProfileCresting the Guest Portal for the Guest SSIDs
  • Network profiles
  • Authentication templates

Module 4: SDA - Policy

  • 2-level HierarchyMacro Level: Virtual Network (VN)Micro Level: Scalable Group (SG)
  • PolicyPolicy in SD-AccessAccess Policy: Authentication and AuthorizationAccess Control PolicyApplication PolicyExtending Policy across domainsPreserving Group Metadata across Campus, WAN and DCEnforcing policy in Firewall domainsCross Domain Policies

Module 5: SDA - Provision

  • Devices OnboardingLifecycle stages of network device discoveryDiscovering DevicesAssigning Devices to a siteProvisioning device with profilesPlug-and-PlayLAN Automation
  • TemplatesTemplates for day 0Templates for day N operations
  • IP TransitsHow to connect the Fabric Sites to the external networkCreating the IP TransitConsiderations for a SD-Access Border Node DesignBGP Hand-Off Between Border and Fusion
  • Fabric DomainsUnderstanding Fabric Domains and SitesUsing Default LAN Fabric DomainCreating Additional Fabric Domains and Sites
  • Adding NodesAdding Fabric Edge NodesAdding Control Plane NodesAdding Border Nodes

Module 6: SDA - Assurance

  • Overview of DNA Assurance
  • Cisco Catalyst Center Assurance- Use Cases Examples
  • Network Health & Device 360
  • Client Health & Client 360
  • Application Health & Application 360
  • Cisco SD- Application Visibility Control (AVC) on Catalyst Center
  • Proactive troubleshooting using Sensors

Module 7: Cisco SD-Access Distributed Campus Design

  • Introduction to Cisco SD-Access Distributed Campus Design The Advantage?
  • Fabric Domain vs Fabric Site
  • SD-Access Transits:IP-Based TransitCisco SD-Access TransitCisco SD-WAN Transit
  • Deploying the Cisco Distributed Campus with SD-Access TransitSite considerationsInternet connectivity considerationsSegmentation considerationsRole of a Cisco Transit Control Plane
  • Cisco SD-Access Fabric in a BoxThe need for FiaBDeploying the FiaB

Module 8: Cisco SD-Access Brownfield Migration

  • Cisco SD-Access Migration Tools and Strategies
  • Two Basic Approaches:Parallel Deployment ApproachIncremental Deployment Approach
  • Integration with existing Cisco ISE in the network Things to watch out for!
  • Choosing the correct Fusion DeviceExisting Core as FusionFirewall as Fusion
  • When do you need the SD-Access Layer-2 Border?L2 Border Understanding the requirementDesigning and Configuring the L2 BorderL2 Border Not a permanent solution

Module 9: Cisco Catalyst Center Automation- Use Cases Examples

  • DAY0: Onboarding new devices using Zero Touch Deployment
  • DAY1: Configurations using Templates
  • DAYN: Security Advisories based on Machine Reasoning Engine
  • DAYN: Simplified Software Management based on Golden Images
  • DAYN: Defective Device Replacement - RMA

Module 10: 3rd Party Integrations

  • ServiceNowIntegrationManagement
  • InfoBlox IPAMIntegrationManagement

Module 11: Specific Use Cases

  • Use Case: STACK LAN Automation
  • Use Case: Silent Hosts
  • Use Case: Wake on LAN
  • Use Case: The need for L2 flooding
  • Use Case: Multicast in the SD-Access Fabric

Module 12: Cisco SD-Access Multi-Domain Integrations

  • Cisco SD-Access to ACI IntegrationsPhase-1: Policy Plane IntegrationPhase-2: Data Plane Integration
  • Cisco SD-Access to Cisco SD-WAN IntegrationsWhat is possible today? SD-WAN Transit setup.Phase-1: The one box solutionPhase-2: The two box solution

Module 13: Troubleshooting

  • Fabric
  • Layer 3 forwarding
  • Layer 2 forwarding
  • Multicast Forwarding
  • Security in the Fabric
  • Troubleshooting Multi-Site Deployments

Lab Outline:

  • Lab 1: SDA Fundamentals
  • Lab 2: Using the Catalyst Center Discovery Tool
  • Lab 3: Using the Catalyst Center Inventory Tool
  • Lab 4: ISE and Catalyst Center Integration
  • Lab 5: Using the Catalyst Center Design Application
  • Lab 6: Using the Catalyst Center Policy Application
  • Lab 7: Fabric Provisioning
  • Lab 8: Wired and Wireless Host and Access Point Onboarding Configuration
  • Lab 9: Configuring External Connectivity Using Fusion Router
  • Lab 10: Configuring Cisco ISE Policies for User Onboarding
  • Lab 11: Onboarding and Provisioning Access Points
  • Lab 12: Fabric and Segmentation Verification
  • Lab 13: Layer-2 Border Fundamentals
  • Lab 14: Configuring a Layer-2 Border to Extend the Same IP Pool
  • Lab 15: Transitioning the Traditional User to the SDA Anycast Gateway
  • Lab 16: Testing IP Connectivity between SDA User and Traditional User
  • Lab 17: Introduction to SDA Distributed Campus
  • Lab 18: Configuring an SDA-Transit and the Transit Control Plane (TCP)
  • Lab 19: Designing a Second Fabric Site
  • Lab 20: Deploying a Second Fabric Site Fabric in a Box
  • Lab 21: Deploying a New Fabric Edge using LAN Automation
  • Lab 22: Automate Network Devices Using Day-N Template
  • Lab 23: Add as Edge Node to Fabric Site-2
  • Lab 24: Host Onboarding at Fabric Site-2
  • Lab 25: Connecting the two Fabric Sites Using the SDA-Transit
  • Lab 26: Testing IP Connectivity and Micro-Segmentation between Fabric Site-1 and Fabric Site-2
|
View Full Schedule

Schedule

9 options available

  • Guaranteed to Run
    Apr 7, 2025 - Apr 11, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Guaranteed to Run
    May 19, 2025 - May 23, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Jun 23, 2025 - Jun 27, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Jul 21, 2025 - Jul 25, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Aug 18, 2025 - Aug 22, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Sep 8, 2025 - Sep 12, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Oct 6, 2025 - Oct 10, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Nov 3, 2025 - Nov 7, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Dec 8, 2025 - Dec 12, 2025 (5 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote

FAQ

Does the course schedule include a Lunchbreak?

Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does Ascendient Learning deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

What does vendor-authorized training mean?

As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.

Is the training too basic, or will you go deep into technology?

It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.

How up-to-date are your courses and support materials?

We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.

Are your instructors seasoned trainers who have deep knowledge of the training topic?

Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.

Do you provide hands-on training and exercises in an actual lab environment?

Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.

Will you customize the training for our company’s specific needs and goals?

We will work with you to identify training needs and areas of growth.  We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.

How do I get started with certification?

Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.

Will I get access to content after I complete a course?

You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.

How do I request a W9 for Ascendient Learning?

View our filing status and how to request a W9.

Reviews

had a good time with the course, however some topics were left out due to the compact amount of time for training.

Great instructor, clear and concise course. Labs were easy to follow and worked perfectly.

Course was great and informative. The instructor had a good flow and was very personable.

They were very good. They made sure everyone was able to get into the training and got all of the material needed for class.

Simply great training provider that I can go for updating/acquiring my skill sets.