SD-Access Underlay: Manual vs LAN Automation
The SD-Access underlay is just a well-built IGP giving every fabric node loopback reachability. Compare building it manually vs with LAN Automation, and see what truly needs Catalyst Center.
The SD-Access underlay is just a well-built IGP giving every fabric node loopback reachability. Compare building it manually vs with LAN Automation, and see what truly needs Catalyst Center.
Five MPLS L3VPN and DMVPN ticket scenarios, each isolated layer by layer: IGP, LDP, MP-BGP, NHRP, IPsec, and the routing on top. The faults and diagnostic commands come from real lab builds.
MPLS gives you a private SLA-backed core; DMVPN gives you cheap encrypted connectivity over any internet link. This article compares the two honestly and shows the standard hybrid designs most enterprise WANs end up running.
IKEv1 and IKEv2 configured on the same DMVPN in a CML lab, with real SA output shown side by side. The migration turns out to be a single-line profile swap, and you see exactly why IKEv2 negotiates faster.
A dual-hub DMVPN can black-hole spoke-to-spoke traffic for two hours after a hub fails because of one default timer. This post builds the design in CML, fails a hub, and shows exactly what breaks and how to fix it.
When two customer sites share an AS number, BGP loop prevention breaks their MPLS L3VPN on purpose. Reproduce the failure in a CML lab and fix it three ways: as-override, allowas-in, and SoO, with real output for each.
6VPE carries IPv6 L3VPN across an IPv4 MPLS core using the same VRFs, RTs, and MP-BGP sessions you already run. This article builds it in CML and shows the two-label stack that makes it work.
Five Layer 2 faults built and broken in a CML lab, ticket style: VLANs, trunks, and a spanning tree quietly blocking the port you need. Real show output, real syslog messages, and the real fix for each one.
SDM templates, errdisable recovery, and CAM aging: the unglamorous switch administration features that prevent table-full errors, dead ports, and mystery flooding, with real output from a CML lab.
ARP believes any answer it hears, which is why ARP spoofing works. Dynamic ARP Inspection and IP Source Guard fix that using the DHCP snooping binding table. Real CML output, plus an honest note on what a virtual switch can enforce.
DHCP snooping builds the binding table that DAI and IP Source Guard depend on. You see how the table populates, trusted vs untrusted ports, Option 82, and verification, with real CML output and an honest platform limitation.
One flooding host can saturate an entire VLAN. Storm control caps broadcast, multicast, and unknown-unicast rates per port; this covers the configuration, both threshold styles, the right action, and an honest note on platform support.