Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2AutomationMedium
A network architect is designing a greenfield campus network using Cisco SD-Access. The goal is to automate the provisioning of user and device access across different departments with varying security policies. Which SD-Access component is responsible for defining and enforcing these group-based access policies?
- ACisco DNA Center
- BBorder Node (BN)
- CControl Plane Node (CPN)
- DPolicy Enforcement Point (PEP)
Show answer & explanationAnswer & explanation
Correct answer: A. Cisco DNA Center
Cisco DNA Center is the centralized management and orchestration platform for Cisco SD-Access. It's where network administrators define and manage all policies, including group-based access policies (SGTs), which are then translated and pushed to the underlying network devices for enforcement.
Why the other options are wrong
- B. A Border Node (BN) connects the SD-Access fabric to external networks and performs policy enforcement at the fabric boundary, but policies are defined in DNA Center.
- C. A Control Plane Node (CPN) provides host reachability information, mapping endpoints to their locations, but does not define access policies.
- D. A Policy Enforcement Point (PEP) is a logical function (often within an Edge Node) that enforces policies, but it doesn't define them.
Cisco DNA Center in SD-Access
Cisco DNA Center is the controller and management platform for Cisco SD-Access. It provides a single user interface for designing, provisioning, applying policy, and assuring the network, translating business intent into network configurations.
- Centralized management and orchestration.
- Policy definition (e.g., SGTs, VNIs).
- Network design, provisioning, and assurance.
- Translates business intent into network configurations.
Memory trick: DNA Center is the brain that writes the rules.