Examining Cisco Enterprise Network Architecture
1. Cisco Enterprise Architecture Modules
Modular design isolates fault domains (failures stay within a module), simplifies upgrades, and standardizes security/QoS policies.ç
Enterprise Campus
-
Structure: Uses the classic 3-Tier Hierarchy (Access, Distribution, Core).
-
Data Center Submodule: Centralizes core enterprise services (Application, File, Email, DNS, Network Management). Built on a modern Spine-Leaf architecture.
Enterprise Edge (Explicitly split into two main blocks in the diagram)
-
Internet Edge Submodule: Manages direct public internet connectivity across one or more ISPs, hosting firewalls and internet-facing services.
-
WAN Edge Submodule: Manages high-performance site-to-site connectivity using purchased WAN services (MPLS, Metro Ethernet, SONET) and QFP routing infrastructure.
-
Services: Provides VPN termination (Remote Access & Site-to-Site) and perimeter firewalls.
Service Provider Edge
-
Represents the third-party transit networks bounded by Service Level Agreements (SLAs):
-
ISP
-
WAN Provider MetroEthernet
-
WAN Provider MPLS
-
Remote Locations
-
Geographically distant endpoints connected back to the Enterprise Edge:
-
Remote Worker / Teleworker: Connected over the Internet Edge via remote VPN.
-
Branch Offices: Connected via MetroEthernet or MPLS to the WAN Edge.
-
Remote Data Centers.
-
2. Four Pillars of Design
-
Self-Healing: Continuously online; automatically isolates failures and restores service.
-
Self-Defending: Embedded security protecting enterprise infrastructure, traffic, and endpoints.
-
Self-Optimizing: Dynamically adapts to workload changes beyond static baseline capabilities.
-
Self-Aware: Leverages deep network visibility to drive automated operational decisions.
3. High-Yield Hardware & Media Trends
Multi-Gigabit & Cable Infrastructure
-
802.11ac Wave 2 / Wi-Fi 6 APs demand speeds exceeding 1 Gbps.
-
IEEE 802.3bz (Multigigabit): Delivers 2.5 Gbps and 5 Gbps speeds over existing Cat5e/Cat6 copper cabling using Cisco Catalyst Multigigabit technology (eliminating expensive cable upgrades).
Power over Ethernet (PoE)
-
Cisco UPOE (Universal PoE): Delivers up to 60W per port for high-power devices (cameras, VDI terminals, lighting, APs).
-
Perpetual PoE: Keeps connected devices powered continuously even when the switch undergoes a software upgrade or reboot.
-
Catalyst 9000 Series: Access layer switches support Perpetual PoE and are hardware-ready for 100W per port.
Bandwidth Scaling & Compliance
-
Aggregation Growth: Core and distribution links must scale from 10 Gbps to 40 Gbps to 100 Gbps over time.
-
MACsec: Layer 2 hardware encryption for compliance and data protection.
-
NetFlow: Provides deep traffic telemetry for network analytics and monitoring.
-
Segmentation: Employs Cisco TrustSec and network virtualization to isolate IoT/IoE endpoints safely.
4. Software-Defined & Automation Platforms
-
Cisco DNA Center (Catalyst Center): Centralized controller using open APIs to automate configuration, policy enforcement, and network assurance.
-
Cisco SD-Access (Software-Defined Access): The campus fabric foundation that unifies wired and wireless networks under a single policy framework (automated onboarding, segmentation, guest access).
-
Cisco SD-WAN: Open, cloud-based overlay managed via the Cisco vManage console to connect Campuses, Data Centers, Branches, and Colocation facilities over any WAN transport.
