Provision Your Network

Provisioning

After you have configured policies for your network in the Cisco Digital Network Architecture (DNA) Center, you must provision your devices. In this stage, you deploy the policies across your devices.

There are 3 aspects of provisioning the devices:

  • Assign the devices to the inventory and deploy the required policies.

  • Add the devices to the sites.

  • Create fabric domains and add devices to the fabric.

Add Devices to Sites

Procedure
    Step 1   From the Cisco DNA Center home page, click Provision. The Inventory page displays device information gathered during the discovery process.
    Step 2   Check the check box next to the device(s) for which you want to associate to a site.
    Step 3   From the Action menu, choose Add to Site.
    Step 4   In the Find Site field, type the name of the site to which you want to associate the device(s). If you selected multiple devices that you want added to the same site, click the All Same Site option.
    Step 5   Click Assign.

    Provisioning Devices

    Provision a Cisco WLC

    Before You Begin

    Procedure
      Step 1   From the DNA Center home page, Choose Provision > Devices .

      The Device Inventory window appears.

      Step 2   Click the Device Inventory tab. All the discovered controllers are displayed.
      Step 3   Check the check box(es) adjacent to the controller device name that you want to provision.
      Step 4   From the Action drop-down list, choose Provision.
      Step 5   In the Assign Site window, assign a site for the controller. In the Find Site field, enter the name of the site to which you want to associate the controller. To assign multiple controllers to the same site, check the All Same Site check box.
      Step 6   Click Next.

      The Configuration window appears.

      Step 7   In the Managed AP Locations field, enter the AP locations managed by controller. Here you have the option to change, remove, or reassign the site.
      Step 8   Click Next.
      Step 9   The Summary window displays the following information:
      • System Details

      • Global Settings

      • SSID

      • Managed Sites

      Step 10   Click Deploy to provision the controller. The Status column in the Device Inventory window shows SUCCESS after a successful deployment.
      Note   

      After provisioning, if you want to make any changes, click Design, change the site profile, and provision the controller again.


      What to Do Next

      1. Add Cisco WLC to a fabric domain. See Add Devices to a Fabric.

      2. Configure settings for the various kinds of devices ("hosts") that can access the fabric domain. See Configure Host Onboarding.

      Provision a Cisco AP - Day 1 AP Provisioning

      Before You Begin

      Make sure you have Cisco AP in your inventory. If not, discover APs using the Discovery function. (See Discover Your Network.)

      Procedure
        Step 1   From the DNA Center home page, choose Provision > Devices.

        The Device Inventory window appears.

        Step 2   Click the Device Inventory tab. All the discovered controllers are displayed.
        Step 3   Check the check box(es) adjacent to the AP device name that you want to provision.
        Step 4   From the Action drop-down list, choose Provision.
        Step 5   In the Assign Site window, assign an AP to the site . In the Find Site field, enter the name of the site to which you want to associate the AP. To assign multiple APs to the same site, check the All Same Site check box.
        Step 6   Click Next.

        The Configuration window appears.

        Step 7   From the AP Rule drop-down list, choose the RF profile for the AP. The options are: High, Typical, and Low. The AP group is created based on the RF profile selected.
        Step 8   Click Deploy to provision the AP.

        You are prompted with message saying that Creation/modification of AP groups in progress. After completion, these devices will go for a reboot.

        Step 9   Click OK. The Status column in the Device Inventory window shows SUCCESS if a deployment is successful.

        Delete Devices After Provisioning

        • If you are deleting a device that is already been added to fabric domain, remove it from the fabric domain and then delete it from the Provision menu.

        • You cannot delete a device from the Inventory window if they have been provisioned. You must delete these devices from the Provision menu.

        Procedure
          Step 1   From the DNA Center home page, choose Provision > Devices.

          The Device Inventory page appears.

          Step 2   Click the Inventory tab, which lists all the discovered and provisioned devices.
          Step 3   Check the check box adjacent to the devices(s) that you want to delete.
          Note   

          APs are deleted only when the controller to which they are connected to is deleted.

          Step 4   From the Action drop-down list, choose Delete Device. You are prompted with a message Devices selected will be deleted. Are you sure you want to proceed ! .
          Step 5   Click OK.

          Configuring Fabric Domains

          Fabrics Overview

          A fabric is a logical group of devices that is managed as a single entity in one or multiple locations. Having a fabric in place enables several capabilities, such as the creation of virtual networks and user and device groups, and advanced reporting. Other capabilities include intelligent services for application recognition, traffic analytics, traffic prioritization, and steering for optimum performance and operational effectiveness.

          The DNA Center allows you to add devices to a fabric network. These devices can be configured to act as controle plane or border devices within the fabric network.

          Before You Begin

          Ensure that your network has been designed, the policies have been retrieved from the Integrated Services Engine (ISE) or created in the DNA Center, and the devices have been inventoried and added to the sites.

          Create a Fabric Domain

          The DNA Center creates a default fabric domain called Default LAN Fabric.

          To add a new fabric domain:

          Procedure
            Step 1   From the DNA Center Home page, click Provision.
            Step 2   Click the New Fabric tab.
            Step 3   Enter a name for the fabric.
            Step 4   From the Select Auth field, select an authentication protocol. This determines the type of access that devices can have when connecting to the network. The protocol selected here is applied to all devices in the fabric.
            Step 5   Click Add.

            Configure a Fabric Domain

            You can add devices and associate virtual networks to a fabric domain, and add multicast address pools.

            Add Devices to a Fabric

            After you have created a fabric domain, you can add devices to this fabric. You can also specify whether the devices should act as a control plane node, a border node, or both.


            Note


            It is optional to designate the devices in a fabric domain as control plane nodes or border nodes. You may have devices that do not play these roles. However, every fabric domain must have at least one controle plane node device and one border node device.

            There are 3 steps to add and configure devices to a fabric domain:

            1. Select the devices.

            2. Specify devices to act as a control plane nodes.

            3. Specify devices to act as border nodes.

            To add a device to the fabric:

            Before You Begin

            You must provision the device. To provision a device, click on the Provision tab and select Devices.

            Procedure
              Step 1   From the DNA Center Home page, click Provision . The screen displays all provisioned fabric domains.
              Step 2   From the list of fabric domains, select a fabric. The screen displays all devices in the network that have been inventoried. You can view the devices in topology view or list view. In topology view, any device that is added to the fabric is in blue color.
              Step 3   Click on a device and select one of the options displayed.

              Field

              Description

              Add to Fabric

              Add a distribution or access device to the fabric domain.

              Add as CP

              Add a core or distribution device as a control plane node. This allows the fabric access device to communicate with the control plane device.

              Add as Border

              Add a core device as a border node. This allows the fabric access device to communicate with the fabric border device.

              In the pop-up window, enter the following options:

              • Set as default border—Select the check box if you want the device to act as a default border node.

              • Routing Protocol—Select the routing protocol for the device.

              • Routing Process—Select the routing process for the device.

              Add as CP+Border

              Add the selected device as a control plane and a border node.

              In the pop-up window, enter the following options:

              • Set as default border—Select the check box if you want the device to act as a default border node.

              • Routing Protocol—Select the routing protocol for the device.

              • Routing Process—Select the routing process for the device.

              View Info

              Displays the details of the selected device.

              Device Role

              Specify the role for the device.
              Step 4   After you have added the devices, click Save.

              Configure Host Onboarding

              The Host Onboarding tab allows you to configure settings for the various kinds of devices ("hosts") that can access the fabric domain.

              In this tab, you can:

              • Select an authentication template that will apply to the fabric. These templates are pre-defined configurations that are retrieved from the ISE.

              • Associate IP address pools to virtual networks.

              • Specify wireless SSIDs within the network that the hosts can access.

              • Apply specific configurations for each port for each access device within the fabric domain.

              Select Authentication Template

              You can select the authentication template that will apply for all devices in the fabric domain.

              Procedure
                Step 1   From the Auth Template section, select the authentication template.
                Step 2   Click Save.

                Associate Virtual Networks to the Fabric Domain

                IP address pools enable host devices to communicate within the fabric domain.

                When an IP address pool is configured, the DNA Center immediately connects to each node to create the appropriate SVI (switch virtual interface) to allow the hosts to communicate.

                You cannot add an IP address pool, but you can configure a pool from the ones that are listed. The IP address pools listed here were created when the network was designed.

                To associate a virtual network to the fabric domain:

                Procedure
                  Step 1   From the Virtual Networks section, click on a virtual network.
                  Step 2   Configure the virtual network.
                  Field Description
                  Select address pools From the list of IP address pools, select the ones that should be part of the virtual network.
                  Choose Auth From the dropdown, select the authentication type for the virtual network when it is associated with the fabric domain.
                  Choose Traffic Type From the dropdown, select whether voice or data traffic should be sent through the virtual network.
                  Wireless Mgmt Pool Select whether the virtual network should be part of the wireless management pool of the fabric domain.
                  AP Provisioning Pool Select whether the virtual network should be part of the access point provisioning pool.
                  Flood and Learn Enable Flood and Learn behaviour for the gateway.
                  Step 3   Click Update to save the settings. The settings you specify here will be deployed to all the devices on the network.
                  Step 4   When all virtual networks have been configured, click Save.

                  Configure Wireless SSIDs for the Fabric Domain

                  The Wireless SSID section allows you to specify wireless SSIDs within the network that the hosts can access.

                  Configure Ports Within the Fabric Domain

                  The Select Port Assignment section allows you to configure each access device on the fabric domain. You can specify network behavior settings for each port on each device.


                  Note


                  The settings you make here for the ports will override the general settings you have made for the device in the Virtual Networks section earlier.

                  To configure the ports:

                  Procedure
                    Step 1   From the Select Fabric Device section, select the access device that you want to configure. The ports available on the device are displayed.
                    Step 2   Select the ports on the device and specify the allowed IP address pool, the groups that have been provisioned, the voice or data pool, and the authentication type for the port.
                    Step 3   When you have specified the settings for the ports, click Save to save the settings for the device.

                    Configure Multicast Settings

                    After devices have been added to the fabric domain, you can create multicast IP address pools and rendezvous points.

                    Multicast IP address pools group the endpoints in the fabric domain.

                    A Rendezvous Point (RP) is a router in a multicast network domain that acts as a shared root for a multicast shared tree. Any number of routers can be configured to work as RPs and they can be configured to cover different group ranges. For correct operation, every multicast router within a Protocol Independent Multicast (PIM) domain must be able to map a particular multicast group address to the same RP.

                    Create a Multicast IP Address Pool

                    To create a multicast IP address pool:

                    Procedure
                      Step 1   From the DNA Center Home page, click Provision . The screen displays all provisioned fabric domains.
                      Step 2   From the list of fabric domains, select a fabric. The screen displays the devices in the network. Any device that is added to the fabric is highlighted in blue color.
                      Step 3   Go to the Advanced Settings tab. The Select Multicast Address Pool displays all IP address pools that have been created.
                      Step 4   Click the Add button. You can now specify the multicast addresses that should form a pool.

                      Field

                      Description

                      Subnet / Mask

                      Enter the subnet IP address and subnet mask for the multicast pool.

                      Contexts

                      Select one or more contexts or VRFs that this multicast pool will become a part of.

                      Step 5   Click OK.
                      Step 6   Click Save on the main screen.

                      Add a Device as Rendezvous Point

                      To add a Device as rendezvous point:

                      Procedure
                        Step 1   From the DNA Center Home page, click Provision . The screen displays all provisioned fabric domains.
                        Step 2   From the list of fabric domains, select a fabric. The screen displays the devices in the network. Any device that is added to the fabric is highlighted in blue color.
                        Step 3   Go to the Advanced Settings tab and scroll down to the Rendezvous Points section.
                        Step 4   Click on a router that you want to add as a rendezvous point and select Make Rendezvous Point.
                        Step 5   Click Save on the main screen.