Enterprise Campus Network Design
Enterprise Campus Network Design
Edge
Core
Access
MDF 1
BRKENS-1501
1 What is a Campus Network?
2 1-2-3 or 4+ Tier Design
3 ECMP vs. StackWise
Agenda 4 MPLS vs. EVPN vs. SD-Access
5 Wireless & Security Notes
6 Summary & References
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Campus Baseline
Campus Networks
DC ISP
What is “Campus”?
WAN
• Edge
• Chassis Types
Access
Campus Cabling
MDF 1
• PIN Features
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
What is a “Campus”?
The basic Merriam-Webster definition of a Campus is:
A group of one or more buildings, and surrounding grounds,
where people and their belongings work together.
Common examples are Hospitals & Research Centers,
Schools & Universities and Corporations & Offices.
Using this - it’s clear a Campus Network is focused on:
• People (Users, Vendors, etc.)
• People's devices (PCs, Phones, Printers, etc.)
• Similar geographic area (LAN, WLAN or MAN, etc.)
• Access to other domains (WAN, ISP, DC & Cloud, etc.)
www.cisco.com/c/en/us/solutions/cisco-on-cisco/enterprise-networks.html
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Campus Networks
Building MDF/IDF & Wiring Closets
www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/campus-wired-wireless.html
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Campus ≠ Data-Center
One or few large buildings nearby. Usually a single floor.
www.cisco.com/c/en/us/solutions/cisco-on-cisco/enterprise-networks.html
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Campus Networks - Real Life
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Campus PINs & Topology
BGP, MPLS
BGP, EVPN BGP, IGP
Core
CoreInterconnect
Interconnect
Core
Core++Edge
Edge
Collapsed
CollapsedCore
Core Campus
CampusDistribution
Distribution
STP STP
Campus
CampusAccess
Access
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Campus Multi-Layer Model
• Few MAN (High-Speed) or WAN (Low-Speed) Uplinks
• Internal & External Autonomous Systems
CORE +
•
• Power Over Ethernet, Integrated Wireless, etc.
• L2 Security, QoS & Flexible NetFlow
• Virtualization: Stack, VLAN, STP / REP, SDA etc.
Catalyst 9400 Catalyst 9300 Catalyst 9200 • Many Low - Medium Speed LAN Downlinks
Modular Fixed
PROs CONs PROs CONs
• More Flexible • More Complex • Less Complex • Less Flexible
• Longer Life-Cycle • BW limit by Chassis • Swap Chassis for BW • Shorter Life-Cycle
• Higher Port Density • Slow(er) Dev & Test • Faster Dev & Test • Lower Port Density
• More Power/Cooling • Lower MTBF • Higher MTBF • Less Power/Cooling
• Redundant Processors • Higher COGs • Lower COGs • Single Processor
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Copper vs. Fiber Media www.cisco.com/c/en/us/products/interfaces-modules/transceiver-modules/
RJ45 (Access to Endpoints) SFP (Access & Distribution) QSFP (Core & Edge)
www.cisco.com/c/en/us/products/collateral/switches/catalyst-9000/nb-06-cat9000-panduit-cables-wp-cte-en.html
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Campus Networks
L2/L3 Unicast Technologies
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Campus Networks
L2/L3 Multicast Technologies
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Cisco Catalyst 9000 Switching Portfolio 2023
One Family from Access to Core – Common Hardware & Software
C9500X-60L4D
C9600X-LC-32CD
Catalyst
Catalyst 9600X
Catalyst Catalyst
9300X
9400X
Catalyst 9500X
Catalyst
Catalyst
9000 Catalyst
Catalyst
9600 Series
Catalyst 9400 Series
9200 Series
9300 Series
Series 9500 Series
Catalyst
9300LM
Catalyst
9200CX Cisco Cisco
ASIC IOS® XE
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Campus Baseline
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Campus Core (Baseline)
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Campus Core Interconnect
10/25/40G
The Interconnect PIN (Tier 4) is an extension of the 100/400G
Access L2
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Campus Core + (SP/WAN) Edge
The Core-Edge PIN (Tier 4) focuses on connecting
multiple Campus areas to SP/WAN (remote domains) ISP WAN
and/or to the Internet.
MP-BGP + MP-BGP +
• Other names: Edge Device, Internet Edge DC 1 L2/L3VPN L2/L3VPN DC 2
• Common in Medium to Very-Large Campus
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Campus Baseline
Distribution
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Campus Distribution (Baseline)
The Distribution PIN (Tier 2) focuses on connecting
multiple Access layers and the Core layer. DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Campus Collapsed Core
The Collapsed Core (Tier 2) focuses on connecting
multiple Access layers and the WAN/Edge layer. DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Campus Baseline
Access
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Campus Access (Baseline)
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Extended Access (IOT / FTTX)
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Campus Baseline
Campus Architecture
DC WAN ISP
Edge
Core
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Campus Architectures
Control-Plane & Data-Plane Redundancy
1 2 3
ECMP (L2/L3 Paths) EtherChannel (L2/L3 LAG) StackWise (L2/L3 MEC)
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
StackWise Virtual Core/Distro
The StackWise Virtual (SVL) Core PIN focuses on
combining Core and/or Distribution into a single virtual DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
StackWise Access
The StackWise Access PIN focuses on combining
multiple Access switches into a single virtual switch DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Campus Baseline
Campus Solutions
DC WAN ISP
Edge
Core
• MPLS/VPLS (L2/L3VPN)
BGP-EVPN (L2/L3VNI)
Distribution
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Campus Solutions & Designs
Providing additional services (beyond basic PINs)
1 2 3
MPLS (L2/L3VPN) EVPN (L2/L3VNI) SDA (L2/L3VNI + SGT)
• L3 Underlay + L2/L3 VPN Overlay • L3 Underlay + L2/L3 VNI Overlay • L3 Underlay + L2/L3 VNI Overlay
• Virtual Private Networks • Virtual Network Instances • VNIs + Scalable Group Tagging
• L3 VRF-based Segmentation • L2/L3 VNI-based Segments • L2/L3 VNI + SGT Segments
• WAN/Edge + VPN Services • Common WAN/LAN Services • LAN Services + Group-Based Policy
MPLS/VPLS, LDP, SR, MP-BGP, PIC MP-BGP/EVPN, VXLAN, VRF-Lite LISP, VXLAN, MP-BGP, VRF-Lite
MVPN, LSM, Extranet, MSR L2 TRM, L3 TRM, L2 BUM LISP HER, Native, L2 BUM
SSO, NSF/NSR, ECMP, GIR SSO, NSF/NSR, ECMP, GIR SSO, NSF/NSR, ECMP, GIR
VPN-FNF, Uniform/Pipe QoS, PBR, IPACL Fabric-FNF, Uniform QoS, IPACL/OGACL Fabric-FNF, App QoS, SGACL
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
EVPN Border & Spine
The EVPN Border & Spine PIN focuses on connecting
an EVPN Fabric and/or other network domains.
• Typically, the same layer as Core or Edge (Tier 3-4) DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
EVPN Leaf
The EVPN Leaf PIN focuses on connecting Wired
endpoints to an EVPN Fabric domain.
• Typically, the same layer as Access or Extended (Tier 1) DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
SD-Access Border & CP
The SDA Border / CP PIN focuses on connecting an
SDA Fabric and/or other network domains.
• Typically, the same layer as Core or Core/Edge (Tier 3-4) DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
SD-Access Edge
The SDA Edge PIN focuses on connecting
Wired/Wireless endpoints to an SDA Fabric domain.
• Typically, the same layer as Access or Extended (Tier 1) DC WAN ISP
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Campus Baseline
DC WAN ISP
Edge
Core
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Wireless LAN
The Central Wireless PIN focuses on connecting
Wireless APs centrally to one or multiple WLCs.
• WLC is typically connected to Core, Edge or DC (Tier 3+)
Central Wireless
• APs are typically connected to Access (Tier 1) C9800-40/80 VLAN C9500X/9600X SVI
WLC Clusters VLAN SVI
Main goal is to connect Wireless Endpoints (via APs) VLAN Core Switches SVI
to a Wireless LAN (WLAN) - centrally in the network
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Firewalls & ACLs
The Firewall (DMZ) PIN focuses on controlling
access into or out of different network areas.
• Typically connected to Core, Edge or DC (Tier 3+)
Firewalls (DMZ)
• Complex designs may use Distro or Access (Tier 1-2)
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Campus Baseline
Conclusion
DC WAN ISP
Edge
Core
1 2 3 4 5 6
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Campus PINs & Topology
BGP, MPLS
BGP, EVPN BGP, IGP
Core
CoreInterconnect
Interconnect
Core
Core++Edge
Edge
Collapsed
CollapsedCore
Core Campus
CampusDistribution
Distribution
STP STP
Campus
CampusAccess
Access
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Keep Learning! cisco.com/go/cvd
Cisco Validated Design (CVD) cs.co/en-cvds
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Webex App
Questions?
Use the Webex App to chat with the speaker
after the session
How
1 Find this session in the Cisco Events Mobile App
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Fill out your session surveys!
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
• Visit the Cisco Showcase
for related demos
BRKENS-1501 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Thank you