Cisco DNA Center Wireless Automation
Cisco DNA Center Wireless Automation
Wireless Network
Automation with Cisco
DNA Center
Flavio Correa- Technical Solutions Architect
CCIE Wireless #38913 @correaflavio
BRKEWN-2026
#CiscoLiveLA
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda
• Why automation and Network Intuitive
• Introduction to Wireless Next Gen Stack
• Wireless Automation Workflow
• Day N Changes
• Automation with 3rd party and APIs
• Deployment Models
• Key Takeaways
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Other Mobility sessions during this week
• BRKEWN-2010 Introduction to Next Generation Wireless Stack
BRKEWN-2017 RF Fundamentals from WiFi to WiFi6 (11ax) Wireless Networks
Wednesday
#CiscoLiveLA Session ID © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Other Cisco DNA related sessions
• BRKCRS-2046 SD-Access Design and Deployment for Campus and Branches
• BRKCRS-3810 Cisco SD-Access technology deepdive
• BRKCRS-2810 Cisco SD-Access - A Look Under the Hood
• BRKCRS-2188 SDA and SD-WAN Interworking in the Cisco Multi-domain Architecture
• BRKCRS-3811 Cisco SD-Access - Policy Driven Manageability
• BRKCRS-2105 The Hybrid Campus: How to deploy a combined Cisco SD-Access and
Meraki solution
• BRKNMS-2910 Enhance the Security of your network with Cisco DNA Center
• TECCRS-2700 Cisco Digital Network Architecture: Enabling Enterprise networks for
the digitalized business
#CiscoLiveLA Session ID © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
The cost of Doing Business in the Digital World
Enterprise Trends driving Digital
Transformation
Data growth
Connected devices 3.64
7.5B
Threat surface areas Mobility
Devices per IoT Things Cloud
Person Connected
$60B Spent of
Network
Resources Operations
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Why are companies spending so much ?
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Today’s Key Challenges for Wireless Networks
INTENT CONTEXT
Powered Intent-based
by Intent Network Infrastructure
Translate Business Intent
to Network Policy
Automate the management
and provisioning millions of
devices instantly
SECURITY
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Software-Defined Access
DNA Center Automation has great benefits independent of the Secure Fabric and Assurance
Industry Best-Practices Decouple Policy from Network Proactive Issue Identification and
and Policy Compliance Topology Resolution
11
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco DNA Automation
Existing Approach Cisco DNA Approach
Multiple tools for Automation and One Box Solution with closed loop
Assurance Automation
BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
DNA Center Automation - Journey Map
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Introduction to
Cisco Next
Generation
Wireless Stack
Cisco Next Generation Wireless Stack
Catalyst 9800-40
2000 Aps, 32K Clients,
40 Gbps
Catalyst 9800-CL
1000, 3000 or 6000 APs
Catalyst 9800-L 10K, 32K or 64K Clients
250 APs, 5K Clients,
5 Gbps
Catalyst 9800
Embedded Wireless**
200 APs, 4K Clients
Catalyst 9800
Embedded Wireless* Catalyst 9800-CL***
100 APs, 2K Clients 1000 APs, 10K Clients *Supports Local Switching only
**SD-Access only
*** Catalyst 9800 for Public cloud FlexConnect only
Up to 100 APs Up to 250 APs Up to 1000 APs Up to 3000 APs Up to 6000 APs
Powered by the
Cisco RF ASIC
Catalyst 9115 Catalyst 9117 Catalyst 9120
(Wi-Fi 6 certifiable) (Wi-Fi 6 compatible) (Wi-Fi 6 certifiable)
• 4x4 + 4x4 • 8x8 + 4x4 • 4x4 + 4x4
• MU-MIMO, OFDMA • MU-MIMO, OFDMA (only DL) • Cisco RF ASIC
• Spectrum Intelligence • Spectrum intelligence • Dual 5GHz, HDX
• 1 x 2.5 mGig • 1 x 5 mGig • RF signature capture
• TWT • Non Triggered TWT • IoT ready (Zigbee, Thread)
• Integrated Antenna only • Container support for IOT apps
• 1 x 2.5 mGig
• TWT
Remote Site
Wireless Security RF Parameters DCA, TPC, CHDM
Config
RF Profile
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Benefits of the new config model
Reusability
Easy Provisioning Change Management
Config modularized as
With AP attribute Site based filtering
objects
Tagging
Rule-based Tagging
Simplicity For easy Day 1
No inheritance or configuration
containers
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Wireless
Automation
Workflow
Scenario
A large enterprise is refreshing their wireless infrastructure to C9800 across
multiple sites/buildings. Site B
Intent Site C
Site
A
Campus Core
Site F Site H
Site E Site G
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Wireless Deployment Workflow
Profile Mapped to
Site SSIDs and RF
Parameters that
represent wireless
network
Site/Building
AP Mapped to Site
APs inherits the
properties of the Profile
associated to site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Plan
Site Hierarchy & Maps
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Export Sites and Maps from Prime Infrastructure
Export Sites
Step 1 Step 2
Site.CSV
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Export Sites and Maps from Prime Infrastructure
Export Maps
Step 1 Step 2
Maps.tar.gz
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Import Ekahau 10.0.2 Project File into DNAC 1.3.1
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Ekahau Project File information
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Workflow for Un-Matched AP’s
• AP’s that do not match – are still placed on the
map as a Planned AP
• Rich workflow for assignment built in
• Hover over a planned AP and choose Assign
option – opens the AP Assignment dialogue
• AP’s match by name and then by type The
dialogue lists:
• AP’s with similar names
• AP’s with same type
• And all AP’s currently unassigned
• A matched AP assumes the Active AP’s name
and becomes active
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Design Network
Services
Monitoring Services
• Syslog
• Traps
• Netflow and Application Visibility
Credentials
• CLI
• SNMP
• HTTP
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Challenges with Network Services & Credentials
§ Vary by :
§ Location
§ Differences in Network Design
§ Information often stored in Files - Error
Prone
§ Day 2 Updates become a challenge
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Manage Site Hierarchy
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Manage Maps
Add new Floors to the Building and Upload Maps
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Manage Maps
Edit Map Properties & Position AP’s
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Automate Roll Out of Regional Changes
Common Network Settings
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Adhere to Password Compliance Standards
Device Credentials
§ Manage Device
Credentials (CLI),
SNMP Read/Write
Credentials and
Https(s) Credentials
§ All Properties
Inherited and
Overridden at
Sites/Area/Building
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
§ Network Services get
mapped to Sites
Design § Automatic Inheritance
Network manages the settings for
Services YOU
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
AAA/ISE Integration
BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
AAA Server - ISE Integration ?
Objectives and Key Points
• Single pane of management for all AAA/policy administration between
network devices and ISE
• Automate RADIUS/TACACS configuration for network devices.
• Support only one ISE cluster.
• Enable secure services between Cisco DNAC and ISE:
o pxGrid Service to pull the info out of ISE (Uni-Directional)
Obtain TrustSec metadata such as SGT, IP-SGT mappings & TrustSec policy.
o ERS APIs (Bi-Directional Communication)
§ Fetch deployment model from ISE, such as PAN and PSN info
§ Add devices to ISE as network devices
§ Create SGT, IP-SGT mappings & TrustSec policy on ISE
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
?
AAA Server - ISE Integration
Pre-Requisites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
AAA Server - ISE Integration
Add ISE in
EasyQoS DNA-C
Step3d - Trust and Verify
Shared secret
between ISE and
devices for TACACS
or Radius
Policy Preview
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
AAA Server - (Non-ISE) Integration
Key Points:
• Non-ISE server definition:
• ISE running 2.2 or below
• ACS or any third-party AAA Server
• Only automate RADIUS/TACACS
configuration for network devices
• Require to add network devices to AAA
clients manually.
• Can have multiples non-ISE AAA servers
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Network Settings
AAA Settings
TACACS
Policy Service
Node
Policy Admin
Node
RADIUS
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Demo - Network Hierarchy and Network
Settings
What did we do so far ?
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Design Business
Intent for Wireless
Associate AP to AP Groups
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Problem with this approach
Need to manually manage the mapping of AP to AP
Groups
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Network Deployment using Profiles
Site D
WAN/Internet
Site I
Campus Core
Site H
Site E Site F Site G
Services
• SSID
• Guest Network 70%-80% of the WLC
• RF Profiles Config or more
• Deployment mode
Services
(Intent)
Named Capabilities
• Clean Air
• 11k
• 11v
Advanced 20%-30% of the
Capabilities WLC Config or less
CLI Templates
• Customized Features
• Cisco Best Practice Out of the
box
BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Wireless Network Profile - Composition View
• Device Credentials
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Wireless Profile - Design Workflow
Assign
Define
Define Define Create CLI Wireless
Create Wireless
Network Wireless Templates Network
Sites Network
Settings Settings (Optional) Profile to
Profile
Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Design- Wireless Settings
SSIDs
Based on best practices
Wireless Interfaces
Map dynamic interface
to VLAN
RF Profiles
Based on best Practices
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Design- Define Wireless Settings
Create Sites
Define Network
Settings
Define Wireless
3
Settings
Create
Create Templates Enterprise
(Optional)
Wireless SSID
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Design- Wireless Settings
Supported in Cisco DNAC 1.3
Advanced Parameters in SSID
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Design - Define Wireless Settings
Create Sites
Create
Define Network
Wireless
Settings Interfaces
Define Wireless
3
Settings
Create Templates
(Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Design - Define Wireless Settings
Create Sites
Define Network
Settings
Define Wireless
3
Settings
Create RF
Create Templates
(Optional) Profile
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Design - Create Templates
Create Sites
Define Network
Settings
Create Project
Define Wireless
Settings
and Template in
“Template Editor”
Create Templates
4
(Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Design - Create Templates
Create Sites
• Cool programming-like template view for copy/paste and editing.
• Template engine is based on Apache Velocity engine.
Define Network • Use “$” sign to define variable.
Settings
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Design - Create Templates
Form View
Create Sites
• Define detailed info of variable in “Input Form” view.
• Default value of variable will auto populate for user during provisioning.
Define Network
Settings
Define Wireless
Settings
Create Templates
4
(Optional)
Define Wireless
Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Design - Create Templates
Create Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Design - Define Wireless Network Profile
Create Sites
Define Network
Settings
Define Wireless
Settings
Create Templates
(Optional)
Define Wireless
5 Network Profile
Assign Wireless
Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Design - Assign Wireless Network Profile to Sites
Create Sites
Define Network
Settings
Define Wireless
Settings
Create Day-N
Templates (Optional)
Define Wireless
Network Profile
Assign Wireless
6 Network Profile to Sites
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
What did we do so far ?
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Demo – Design
1. Create Wireless Profile with Enterprise SSID
2. Assign Wireless Profile to Site
Provision
APs Discover
Discover Provision
Cisco DNAC Provision APs
WLC WLC to Site
via PnP
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Provision - Discover WLC
1 Discover WLC For C9800 Wireless Controller, minimum configuration
required for successful discovery and management on
Cisco DNA Center are as below:
Provision WLC to
• SSH and NETCONF are enabled
Site
• CLI Login Credentials
• Wireless Management Interface
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Provision - Discover WLC
Provision WLC to
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Provision - Discover WLC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Provision - N+1 HA WLCs
Supported HA Deployment Models:
• 1:1 HA from 1.1 release.
• N+1 from 1.3 release.
• Ensure APs are provisioned with correct primary and secondary WLCs.
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Provision - N+1 HA WLCs
§ The same wireless profile is applied to both primary and secondary WLCs.
§ “Secondary Managed AP Locations” concept is introduced during WLC provision in
1.3.
§ WLC that assigned to be sites with “Secondary Managed AP Locations” acts as
secondary WLC for all APs on that site.
§ Can not provision secondary WLC to a site if there is no primary WLC assigned to it.
§ Claiming APs to a site will provision APs with primary and secondary WLC
automatically.
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Provision - Provision WLC to Site
Discover WLC
Primary
WLC
2
Provision WLC to
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Provision - Provision WLC to Site
Discover WLC
2
Provision WLC to
Site
APs Discover
Cisco DNA
Center via PnP
Provision APs to
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Behind the Scenes …
• SSID creation
WLAN Creation • Dynamic Interface creation
• QoS for Voice/Data
QoS Settings • AVC
• Fastlane
Security • Enterprise/Personal/None
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Provision - Provision WLC to Site On C9800 Wireless Controller
• Country Code
• WLAN and Policy Profiles
• Network Settings:
TACACS, Radius, SNMP,
Syslog, DHCP, DNS, NTP
and etc.
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Provision - Provision WLC to Site
On C9800 Wireless Controller
WLAN
Profile
Policy
Profile
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Behind the Scenes ….
Common Network Settings
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Behind the Scenes ….
Common Network Settings
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Behind the Scenes ….
Common Network Settings
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Behind the Scenes ….
Dynamic Interfaces & WLAN Creation
WLAN/SSID Creation :
Profile name =
<Site Name_SSID_unique#>
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Behind the Scenes ….
WLAN Parameters
§ SSID Creation
§ Automatic association of
Dynamic Interfaces to
WLAN
§ Broadcast SSID
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Behind the Scenes ….
WLAN Parameters - Security Policy
§ WPA2 Enterprise :
WPA2 Policy Enabled + WPA2 Encryption
(AES) + Dot1x enabled
§ WPA2 Personal :
WPA2 Policy Enabled + WPA2 Encryption
(AES) + PSK
§ Open :
Layer 2 Security = None
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Behind the Scenes ..
WLAN Parameters - QoS
§ Automatically enable
AVC for that WLAN
§ Enable Fastlane if
selected
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Behind the Scenes ….
WLAN Parameters - Advanced
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Behind the Scenes ….
RF Profiles
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Provision - Provision WLC to Site
On ISE
Discover WLC
Provision WLC
2 to Site
Provision APs
to Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Summary of attributes applied by DNAC
Enterprise Personal Open Guest-External Guest-ISE
AVC Enabled Enabled Enabled Disabled Disabled
Allow AAA Override Enabled Disabled Disabled Enabled Enabled
Coverage Hole Detection Enabled Enabled Enabled Enabled Enabled
Session Timeout 1800 Disabled Disabled Disabled Disabled
Client Exclusion Enabled Enabled Enabled Enabled Enabled
11ac MU-MIMO Enabled Enabled Enabled Enabled Enabled
11k Neighbor List Enabled Enabled Enabled Enabled Enabled
11k Dual Band Neighbor List Disabled Disabled Disabled Disabled Disabled
MFP Client Protection Optional Optional Optional Optional Optional
NAC State None None None None ISE NAC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Demo- WLC Provisioning
What did we do so far ?
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Provision Workflows
APs Discover
Discover Provision Provision
Cisco DNAC
WLC WLC to Site APs
via PnP
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Provision Workflow - AP
Option - 1 Option - 2
Import a CSV with the AP
Onboard AP - Plug & Play S/N, AP Name, Location, RF
Profile
Provision AP
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Provision Workflow - AP PnP Discovery
Cisco
DNAC IP Cisco DNA Center
Option 43
5A1D;B2;K4;I192.168.139.151;J80
AP
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
PnP Server Discovery Options
Routers
DHCP with option 43 (ASR, ISR)
1
PnP string: 5A1D;B2;K4;I172.19.45.222;J80 added to DHCP Server
Wireless
Automated
Access Points
DNS lookup
2
pnpserver.localdomain resolves to DNA Center IP Address
Switches
(Catalyst®)
3 Redirect
Cloud re-direction https://devicehelper.cisco.com/device-helper
Cisco hosted cloud, re-directs to on-prem DNA Center IP Address
USB-based bootstrapping*
4 router-confg/router.cfg/ciscortr.cfg Manual discovery
not supported for
Manual
Access Points
Option -1
Discover WLC
Provision WLC to
Site
Provision APs to
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Provision- Provision APs to Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Provision- Provision APs to Site
Provision WLC to
AP is configured as FlexConnect AP if
Site any SSID in the site profile is enabled
with “FlexConnect Local Switching”.
Provision APs to
4
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Provision- Provision APs to Site
Provision WLC to
Site
RF profile is used to
generate RF Tag and
Provision APs to
4 associate it to AP.
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Provision- Provision APs to Site
Provision WLC to
Site
Provision APs to
4
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Provision- Provision APs to Site
Sample AP Console Log
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Provision- Provision APs to Site
On C9800 Wireless Controller
Discover WLC
Provision WLC to
Site
Provision APs to
4
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
Provision- Provision APs to Site
Discover WLC
ON C9800 Wireless Controller
Provision APs to
4
Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Provision Workflow - AP’s Option -1
Discover WLC
Provision APs
AP’s get associated to the
to Site WLC and move to the
DNAC Inventory
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Provision Workflow - AP’s Option -1
Discover WLC
Provision WLC
to Site
APs Discover
DNA-C via PnP
Provision APs
to Site
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Behind the Scenes …
AP Groups Creation
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Behind the Scenes …
SSID’s Mapping
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Behind the Scenes …
RF Profiles
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Option - 2 : Bulk AP Deployment
1 Import APs
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
Option - 2 : Bulk AP Deployment
2 Prepare AP Bulk Import CSV and Upload
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Option - 2 : Bulk AP Deployment
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Demo - AP Provisioning
• Network Profiles are mapped to Sites and
Site becomes the glue for Automation
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
What did we do so far ?
Planned the Sites & Hierarchy
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
?
Network Profile Lifecycle
1
UPDATE
PROFILE (v1) PROFILE (v2)
Mismatch
with Profile
2
3
Compliance mismatch
of v1 and v2
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 129
Wireless Profile - Day 2 Changes
V1 of the
Profile
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
IRCM for Guest Anchoring
User Case:
Inter-Release Controller Mobility (IRCM) is critical for mobility roaming and guest
anchoring. With introduction of C9800 IOS-XE WLC, Cisco DNA Center can simplify
both green-field deployment and integration with AireOS WLC, starting guest
anchoring support from 1.3 release.
Foreign Anchor Cisco DNA Center Support
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 131
IRCM for Guest Anchoring
Key Points
• Only one wireless profile required for both Foreign and Anchor WLCs
• In wireless profile, there is at least one SSID required to be specified as guest anchoring
• For Foreign WLC, Cisco DNA Center provision all SSIDs in the profile
• For Anchor WLC, Cisco DNA Center will deploy only guest anchor SSID in profile based
on matching ”Manage AP Location” for Foreign and Anchor WLCs
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
IRCM for Guest Anchoring
Workflow
Design Provision
Provision
Design Guest Provision Anchor
SSID Foreign WLC
WLC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 133
Day 2- IRCM Guest Anchoring
Design Guest SSID C9800s as both
Foreign and Anchor
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 134
Day 2- IRCM Guest Anchoring
Provision Foreign WLC(s) C9800s as both
Foreign and Anchor
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 135
Day 2- IRCM Guest Anchoring
Provision Foreign WLC(s) C9800s as both
Foreign and Anchor
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 136
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Wireless interface
created on anchor WLC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 137
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Note that only guest SSID
will be created on anchor
WLC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 138
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Why?
• Enable guest WLAN and
create anchor configuration
on foreign WLC
• Create guest WLAN and
anchor configuration
• Create mobility peers on
both foreign and anchor
WLCs
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 139
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
On Anchor
What else in WLAN?
• Webauth Parameter Map
• Authentication List
• Preauthentication ACL
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 140
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
On Anchor
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 141
Day 2- IRCM Guest Anchoring
Provision Anchor WLC(s) C9800s as both
Foreign and Anchor
Foreign C9800 WLC is
required to have matching
WLAN profile and policy
profile names as anchor
when C9800 is anchor. it is enabled now.
On Foreign
Anchor to Anchor
C9800
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 142
Day 2- IRCM Guest Anchoring
Provision Mobility Peers C9800s as both
Foreign and Anchor
On Anchor
Foreign WLCs
On Foreign
Anchor WLC
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 143
Demo- Day 2
Implement Foreign and Anchor Guest Solution
Deployment
Models
Same Workflows for different Wireless Branch
Deployments
Configure
Centralized
From a web FlexSetConnect
up Mobility Express
Operate Catalyst 9800
browser or Cisco Controller Next Gen Wireless
Eliminate the need
Ease of Deployment
wireless app, useand Functionality Stack
for a Controller at
management
the setup wizard Embedded in the
every Site
to enable multiple Access Point
APs
simultaneously
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 146
Flex-Based
Deployment
Flex Deployment
Design Network Design Business
Plan
Services Intent
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 148
Behind the Scenes ..
WLC Provisioning
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 149
Behind the Scenes ..
• Unique Flex Group name is generated based on
site names with random number at the end.
• WLAN to VLAN mappings are created.
AP Provisioning
AP Provisioning
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 150
Intent Based
Software Updates
Core Principles of Software
Upgrade with DNA Center
1 2 3
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 152
Software Upgrade Process
Request
Software
Update
Identify
Close CR Golden
Image
Post Select
Deploy Devices
Validations
Activate Create
Software CR
DNA Center
NMS Software
Distribute Approve
Software CR
PreCheck
Validations
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 153
N+1 rolling AP upgrades: Zero client downtime
during image upgrades
Unified management
with Cisco DNA Center Key highlights
Policy Automation Assurance
ü No more manual
intervention to create
groups in Cisco Prime®
Infrastructure
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
AP
N+1 Rolling AP Upgrade
Wireless Controller image upgrade using N+1 staging Controller
Trigger Rolling Upgrade
X
Version : X+1 Mobility Group Version: X+1
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
DNA Center - Software Update Workflow
System
Define Golden Pre-Check
Identifies Software Post Upgrade
Image by Validation for
Devices not in Upgrade Validation
Device Family Disk/Memory
compliance
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 158
Demo
§ Software Images are mapped to Sites
§ Extremely simplified upgrade process
§ Upgrade with Confidence - Integrate with
YOUR Pre-Check/Post-Check scripts
Provisioning § Closed Loop Automation for Software
Images Upgrades
Summary
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 170
DNA Center as a
Platform
The Journey to Intent-based Networking
Increased
IT Agility
Platforms
rm Systems
tf o
Pla
pen nt er
O Ce Products
DNA t ure
co uc
C is r as tr
d Inf
-b ase
t e nt
In
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 172
Platform Capabilities – APIs, Adapters & SDKs
Intent APIs
IT and Network
Assurance Network Inventory /
System Process • •
Discovery /Tagging
• Path Trace
• SDA
ITSM • Command Runner
• Topology
• Template
IPAM Programmer • Plug-n-Play
Reporting • NFV Provisioning • Software Image
Management
• Wireless
(SWIM)
Provisioning
X-Domain Integration
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Introducing Cisco DNA Center Platform
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 174
Introduction Cisco DNA Center Platform
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 175
Intent APIs
Network APIs Business APIs
• Network Level - Features based API • Intent Based API for network operations
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 176
Example of Business Intent API: Create SSID
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 177
API Catalog
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 178
API Usability
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 179
Cisco DevNet and DNA Center
developer.cisco.com
#CiscoLiveLA Session ID © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 180
DNACaaP
ITSM Integration
Streamlining IT Processes
Before After
IT and IT and
Network How do I correlate all this
Network
data – and take the correct
Systems actions?
Systems Let’s code the interactions and
reap the results
ITSM
IT and network
IPAM Human
operations
middleware
orchestrator
Reporting
ITSM
Alerts,
telemetry, IPAM
CLI, scripts
Reporting
Infrastructure Infrastructure
ITSM
Domain API’s
IT Ecosystem
Standardized
Cisco DNA
Center IPAM
Platform
Direct Integration Reporting
Available Today: ITSM(Service Now), IPAM (Infoblox, Bluecat) and Reporting (Tableau)
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 183
DNA Automation / Assurance driven events or
issues translate into ITSM events
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 184
ITSM Event spawns off a problem depending on
impact and user defined criteria
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 186
Key Takeaways
Key Takeaways
• Intent Based Workflows that are WLC Architecture Agnostic
• DNA Center has tight integration with Identity Service Engine (ISE)
• Use Plug and Play for faster and better WLC and AP on-boarding
#CiscoLiveLA BRKEWN-2026 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 189
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 190
Thank you
#CiscoLiveLA
#CiscoLiveLA