Enterprise Network Architecture
Designing scalable, secure and highly available enterprise networks
🏢 Cisco Enterprise Architecture
Enterprise networks connect users, applications, servers, wireless devices, branch offices and cloud resources. The architecture should provide scalability, availability, security and predictable performance.
Three-Tier Architecture
- Access: Connects end devices.
- Distribution: Routing, policy and redundancy.
- Core: High-speed backbone.
Two-Tier Architecture
In smaller environments, distribution and core functions can be combined into a collapsed core.
🔗 Campus LAN
A campus LAN connects users and services inside an organization. Typical technologies include VLANs, trunks, STP, EtherChannel, inter-VLAN routing and first-hop redundancy.
Important Technologies
VLAN 802.1Q STP EtherChannel HSRP VRRP♻️ Network Redundancy
Redundancy prevents a single hardware, interface or link failure from causing network-wide service interruption.
- Dual switches
- Dual uplinks
- EtherChannel
- STP
- HSRP / VRRP
- Dynamic routing
- Multiple WAN paths
Cisco Switching
CAM, switching paths, VLANs and trunking
🔀 Switching Paths
Process Switching
The CPU processes packets individually. It is slower and CPU intensive compared with hardware forwarding.
CEF
Cisco Express Forwarding provides high-speed Layer 3 forwarding. CEF uses the FIB and adjacency table.
- FIB — Forwarding Information Base
- Adjacency Table
🧠 CAM Table
CAM, or Content Addressable Memory, stores MAC address information and associates MAC addresses with switch ports.
show mac address-table show mac address-table dynamic clear mac address-table dynamic
🟦 VLAN
A VLAN logically separates a Layer 2 network into independent broadcast domains.
- VLAN 10 — Users
- VLAN 20 — Servers
- VLAN 30 — Voice
- VLAN 40 — Management
vlan 10 name USERS interface gi0/1 switchport mode access switchport access vlan 10
🚇 Trunking
A trunk carries traffic from multiple VLANs across one physical connection. Cisco networks commonly use IEEE 802.1Q.
interface gi0/24 switchport mode trunk switchport trunk allowed vlan 10,20,30
Important Concepts
- Native VLAN
- Allowed VLANs
- VLAN tagging
- Access port
- Trunk port
🔧 VLAN and Trunk Troubleshooting
show vlan brief show interfaces trunk show interfaces switchport show interfaces status
- Check whether the VLAN exists.
- Check access-port VLAN assignment.
- Check trunk status.
- Check allowed VLAN list.
- Check native VLAN consistency.
- Check encapsulation and negotiation.
STP, RSTP and MST
Preventing Layer 2 loops
🌳 STP
Spanning Tree Protocol prevents Layer 2 switching loops by creating a loop-free logical topology.
Important Concepts
- Root Bridge
- Root Port
- Designated Port
- Blocked/Alternate Port
- Bridge ID
- Path Cost
⚡ RSTP
Rapid STP, defined by IEEE 802.1w, provides faster convergence than traditional STP.
- Root port
- Designated port
- Alternate port
- Backup port
show spanning-tree show spanning-tree root show spanning-tree vlan 10
🧩 Multiple Spanning Tree
MST allows multiple VLANs to share a common spanning-tree instance, reducing STP overhead.
- MST Region
- MST Instance
- VLAN-to-instance mapping
- MST revision number
🛠 STP Troubleshooting
- Identify the root bridge.
- Check port roles.
- Check VLAN consistency.
- Check root priority.
- Check BPDU behavior.
- Check topology changes.
show spanning-tree detail show spanning-tree blockedports show spanning-tree summary
EtherChannel
Link aggregation and Layer 2/Layer 3 redundancy
🔗 EtherChannel
EtherChannel combines multiple physical interfaces into one logical interface called a Port-Channel.
- Higher bandwidth
- Link redundancy
- Load distribution
- STP sees the bundle as one logical link
LACP
LACP is an IEEE standards-based link aggregation protocol.
interface range gi0/1-2 channel-group 1 mode active interface port-channel 1 switchport mode trunk
Modes: active and passive.
PAgP
PAgP is Cisco's proprietary EtherChannel negotiation protocol.
- Desirable
- Auto
show etherchannel summary show interfaces port-channel 1
EIGRP
Implementation, optimization and troubleshooting
🧭 Understanding EIGRP
EIGRP is an advanced distance-vector routing protocol. It uses DUAL to calculate loop-free paths.
Tables
- Neighbor Table
- Topology Table
- Routing Table
DUAL and EIGRP Metrics
- Successor
- Feasible Successor
- Feasible Distance
- Reported Distance
- Feasibility Condition
A feasible successor provides a loop-free backup path and allows fast convergence.
⚙️ Configure EIGRP
router eigrp 100 network 10.0.0.0 0.0.0.255 network 192.168.1.0 0.0.0.255 no auto-summary
🛡 EIGRP Stub
Stub routing limits query propagation and is useful for branch routers.
router eigrp 100 eigrp stub
📈 EIGRP Optimization
- Summarization
- Stub routing
- Metric tuning
- Route filtering
- Query boundaries
- Passive interfaces
🔧 EIGRP Troubleshooting
show ip eigrp neighbors show ip eigrp topology show ip route eigrp show ip protocols
Check AS number, network statements, interfaces, authentication, K-values and passive interfaces.
OSPF / OSPFv3
Link-state routing, multiarea OSPF and optimization
🌐 OSPF Fundamentals
OSPF is a link-state routing protocol. It uses the SPF algorithm to calculate the shortest path.
- Router ID
- LSA
- LSDB
- Cost
- Areas
- DR / BDR
🤝 OSPF Neighbor States
| State | Description |
|---|---|
| Down | No Hellos received |
| Init | Hello received |
| 2-Way | Bidirectional communication |
| ExStart | Master/slave negotiation |
| Exchange | Database descriptions |
| Loading | LSA information exchanged |
| Full | Database synchronized |
🏢 Multiarea OSPF
Large OSPF networks can be divided into multiple areas. Area 0 is the backbone area.
- Internal Router
- ABR
- ASBR
- Backbone Area
- Non-backbone Areas
📚 Link State Database
The LSDB contains topology information learned through LSAs. Routers within the same area maintain synchronized LSDB information.
show ip ospf database show ip ospf database router show ip ospf database summary
🧩 OSPF Stub Areas
- Stub
- Totally Stubby
- NSSA
- Totally NSSA
Stub areas reduce the amount of external routing information inside an area.
⚙️ OSPF Tuning & Optimization
- Cost adjustment
- Reference bandwidth
- Summarization
- Passive interfaces
- Area design
- LSA filtering
interface gi0/0 ip ospf cost 10
🔐 OSPF Authentication
OSPF authentication protects routing adjacencies against unauthorized neighbors.
Study:
- Plain-text authentication
- MD5 authentication
- Cryptographic authentication
🌍 OSPFv3
OSPFv3 is commonly used for IPv6 routing. IPv6 routing relies heavily on link-local addressing.
show ipv6 ospf neighbor show ipv6 ospf database show ipv6 route ospf
🔧 OSPF Troubleshooting
- Area mismatch
- Authentication mismatch
- Hello/dead timer mismatch
- MTU mismatch
- Network type mismatch
- Passive interface
- Incorrect router ID
show ip ospf neighbor show ip ospf interface show ip ospf show ip route ospf
BGP / IBGP / EBGP / MP-BGP
Policy-based routing and advanced path control
🌍 EBGP
External BGP operates between different autonomous systems.
router bgp 65001 neighbor 192.0.2.2 remote-as 65002
🏢 IBGP
Internal BGP operates between routers belonging to the same autonomous system.
Large IBGP networks traditionally require a full mesh, which can be reduced using route reflectors.
🧠 BGP Path Selection
- Weight
- Local Preference
- Locally originated route
- Shortest AS Path
- Origin
- MED
- eBGP over iBGP
- IGP metric to next hop
🚀 BGP Advanced Features
- Prefix lists
- Route maps
- Communities
- Local preference
- MED
- Route aggregation
- Maximum prefix
- Authentication
🔁 Route Reflectors
Route reflectors reduce the need for a full-mesh IBGP design.
A route reflector can reflect selected routes between IBGP clients.
🌐 MP-BGP
Multiprotocol BGP supports multiple address families.
- IPv4
- IPv6
- VPNv4
- VPNv6
🔧 BGP Troubleshooting
show ip bgp summary show ip bgp show ip bgp neighbors show ip route bgp
- Check TCP connectivity.
- Check AS numbers.
- Check neighbor state.
- Check update source.
- Check route policy.
- Check next-hop reachability.
Routing Redistribution
Connecting different routing domains
🔄 Redistribution
Redistribution injects routes learned by one routing protocol into another routing protocol.
EIGRP ↓ Router ↓ OSPF
Route Maps
Route maps provide granular control over redistribution. They can match routes and modify attributes.
- Match prefix
- Set metric
- Set tags
- Filter routes
⚠ Redistribution Issues
- Routing loops
- Metric incompatibility
- Administrative distance
- Suboptimal paths
- Route feedback
Route tagging can help identify routes that have already passed through a redistribution point.
Path Control & PBR
Controlling traffic forwarding decisions
🎯 Policy-Based Routing
PBR forwards traffic based on policies instead of relying only on the routing table.
Possible matches:
- Source address
- Destination
- Protocol
- Access list
🛣 Path Control
Path control can be achieved using:
- BGP attributes
- PBR
- Administrative distance
- Routing metrics
- Route maps
- Prefix lists
HSRP & VRRP
First-hop redundancy
🔥 HSRP
Hot Standby Router Protocol provides a virtual default gateway. One router normally operates as active and another as standby.
interface gi0/0 standby 10 ip 192.168.10.1 standby 10 priority 110 standby 10 preempt
🛡 VRRP
Virtual Router Redundancy Protocol is a standards-based first-hop redundancy protocol.
- Virtual IP
- Master router
- Backup router
- Priority
NAT
Network Address Translation
Static NAT
One inside address maps to one global address.
ip nat inside source static 192.168.1.10 203.0.113.10
Dynamic NAT
Private addresses are translated using a configured pool of public addresses.
PAT
Port Address Translation allows many internal devices to share a single public IP using different TCP/UDP ports.
🔧 NAT Verification
show ip nat translations show ip nat statistics clear ip nat translation *
VRF
Virtual Routing and Forwarding
📦 VRF Concept
VRF creates multiple independent routing tables on a single router or Layer 3 device.
VRF-CORPORATE VRF-GUEST VRF-MANAGEMENT
Benefits
- Traffic isolation
- Multi-tenancy
- Overlapping IP addresses
- Segmentation
- MPLS VPN support
show vrf show ip route vrf NAME
GRE / VTI / DMVPN
Enterprise VPN technologies
🔐 GRE
GRE encapsulates Layer 3 traffic inside a tunnel. It supports routing protocols across the tunnel.
Important: GRE itself does not encrypt traffic.
🔒 VTI
Virtual Tunnel Interfaces provide virtual Layer 3 interfaces that can be used with IPsec.
- Site-to-site VPN
- Dynamic routing
- IPsec
🌐 DMVPN
Dynamic Multipoint VPN provides scalable hub-and-spoke and dynamic spoke-to-spoke connectivity.
- mGRE
- NHRP
- IPsec
- Dynamic routing
MPLS & MPLS L3 VPN
Label switching and VPN architecture
🏷 MPLS
Multiprotocol Label Switching forwards traffic using labels.
- Label
- LSR
- LER
- LSP
- Label switching
🏢 MPLS L3 VPN
CE ── PE ── P ── P ── PE ── CE
Important concepts:
- VRF
- Route Distinguisher
- Route Target
- MP-BGP
- MPLS Labels
Route Distinguisher
An RD makes otherwise overlapping customer prefixes unique inside the VPNv4/VPNv6 routing architecture.
Route Target
RT communities control which VPN routes are imported and exported between VRFs.
Wireless Principles & Deployment
Enterprise Wi-Fi architecture
📡 Wireless Principles
- RF
- Frequency
- Channels
- Channel width
- Signal strength
- Noise
- SNR
- Interference
- Modulation
Common bands:
2.4 GHz 5 GHz 6 GHz🏗 Wireless Deployment
- Autonomous AP
- Controller-based AP
- Cloud-managed wireless
- Centralized management
📶 AP Operation
Access points provide wireless connectivity between clients and the wired network.
- Association
- Authentication
- Encryption
- RF transmission
- Client management
Wireless Roaming & Location Services
🚶 Wireless Roaming
Roaming occurs when a wireless client moves from one AP to another while maintaining connectivity.
- 802.11r
- 802.11k
- 802.11v
📍 Location Services
Enterprise wireless infrastructure can use RF information to determine approximate client/device location.
Applications include:
- Asset tracking
- Client location
- Presence detection
- Analytics
Wireless Client Authentication
🔑 Personal Authentication
WPA2/WPA3 Personal typically uses a pre-shared key.
🏢 Enterprise Authentication
Enterprise wireless commonly uses 802.1X and an authentication server such as RADIUS.
Client ↓ AP / WLC ↓ RADIUS ↓ Authentication Server
- 802.1X
- EAP
- RADIUS
🔧 Wireless Connectivity Troubleshooting
- SSID
- Authentication
- Encryption
- RF signal
- VLAN
- DHCP
- IP address
- DNS
- Roaming
Multicast
📣 Multicast
Multicast allows one sender to efficiently send traffic to multiple receivers belonging to a multicast group.
- Multicast groups
- IGMP
- PIM
- RPF
- Multicast routing table
🔍 Multicast Troubleshooting
show ip mroute show ip pim neighbor show ip igmp groups
Verify group membership, PIM neighbors and reverse-path forwarding.
Quality of Service
⚡ QoS
QoS manages network traffic to provide predictable service for important applications.
- Classification
- Marking
- Queuing
- Congestion management
- Congestion avoidance
- Policing
- Shaping
🎙 Priority Applications
- Voice
- Video
- Business-critical applications
- Interactive applications
Network Services
DHCP
Automatically provides clients with IP configuration.
- IP address
- Subnet mask
- Default gateway
- DNS server
- Lease time
ip dhcp pool USERS network 192.168.10.0 255.255.255.0 default-router 192.168.10.1 dns-server 8.8.8.8
DHCP Troubleshooting
show ip dhcp binding show ip dhcp pool show ip dhcp conflict
- Check VLAN.
- Check DHCP pool.
- Check relay.
- Check address exhaustion.
DNS
DNS translates hostnames into IP addresses.
nslookup example.com dig example.com
NTP
NTP synchronizes device clocks, which is important for logging, security and troubleshooting.
Monitoring & Analysis
📋 Syslog
Syslog provides centralized logging of network events.
| Level | Meaning |
|---|---|
| 0 | Emergency |
| 1 | Alert |
| 2 | Critical |
| 3 | Error |
| 4 | Warning |
| 5 | Notification |
| 6 | Informational |
| 7 | Debugging |
logging host 192.168.1.100 show logging
📊 Flexible NetFlow
Flexible NetFlow provides detailed information about network traffic flows.
- Top talkers
- Source/destination
- Applications
- Protocols
- Traffic volume
- Interfaces
⏱ Cisco IP SLA
IP SLA measures network performance and reachability.
- Latency
- Jitter
- Packet loss
- Response time
- Reachability
⚙ EEM
Embedded Event Manager automatically responds to device events.
Event ↓ EEM detects condition ↓ EEM executes action
Possible actions include executing commands, sending logs and changing configuration.
🔎 Traffic Analysis Tools
ping traceroute show ip route show arp show mac address-table show interfaces show cdp neighbors show lldp neighbors show logging
Infrastructure Security
Protecting enterprise infrastructure
🛡 Infrastructure Security
Enterprise security uses multiple layers of protection.
- Authentication
- Authorization
- Encryption
- Segmentation
- ACLs
- AAA
- Monitoring
- Control-plane protection
🏰 Defense in Depth
Identity ↓ Access Control ↓ Segmentation ↓ Firewall ↓ Monitoring ↓ Threat Detection
Standard & Extended ACLs
Standard ACL
Standard ACLs primarily filter traffic based on source IP.
access-list 10 permit 192.168.10.0 0.0.0.255
Extended ACL
Extended ACLs can filter based on source, destination, protocol and port.
access-list 101 permit tcp 192.168.10.0 0.0.0.255 any eq 443
ACL Rules
- ACLs are processed sequentially.
- First matching statement is used.
- There is an implicit deny at the end.
- Place specific entries before general entries.
AAA
Authentication, Authorization and Accounting
Authentication
Who are you?
Authorization
What are you allowed to do?
Accounting
What did you do?
AAA Protocols
- RADIUS
- TACACS+
Control Plane Protection
🛡 CoPP
Control Plane Policing protects the router CPU from excessive or malicious traffic.
- Classify traffic
- Apply policy
- Rate-limit unwanted traffic
- Protect routing protocols
Threats
- CPU exhaustion
- DoS attacks
- Excessive control-plane traffic
- Unauthorized protocol traffic
Python Programming
Networking automation fundamentals
🐍 Python Basics
- Variables
- Strings
- Lists
- Dictionaries
- Conditions
- Loops
- Functions
- Modules
- Exception handling
Python Example
device = "Router1"
ip = "192.168.1.1"
print("Connecting to", device)
print("IP:", ip)
JSON & APIs
JSON
JSON is a lightweight structured data format widely used with network automation and APIs.
{
"hostname": "R1",
"interface": "GigabitEthernet0/0",
"ip": "192.168.1.1"
}
APIs
An API allows software applications to communicate with network systems.
Automation Tool
↓
API
↓
Network Device
- GET
- POST
- PUT
- PATCH
- DELETE
NPP
Place NPP in the programmatic-networking section of your study material and associate it with the terminology used by the specific Cisco course/version you are studying.
NETCONF & RESTCONF
NETCONF
NETCONF is a network management protocol designed for programmatic configuration and retrieval of device data.
- SSH transport
- XML messages
- YANG data models
- Structured configuration
RESTCONF
RESTCONF provides REST-style access to configuration and operational data.
- HTTP/HTTPS
- JSON
- XML
- YANG
| Method | Typical Purpose |
|---|---|
| GET | Read |
| POST | Create |
| PUT | Replace |
| PATCH | Modify |
| DELETE | Delete |
Cisco DNA Center
Automation and network assurance
🧠 DNA Center
Cisco DNA Center provides centralized management, automation, policy and assurance for enterprise networks.
- Network discovery
- Device configuration
- Automation
- Monitoring
- Assurance
- Policy
Network Assurance
Assurance provides visibility into network health, client experience, applications and infrastructure.
Cisco SD-Access
🔷 SD-Access
SD-Access uses software-defined networking concepts to automate and secure campus networks.
- Underlay
- Overlay
- Fabric
- Identity
- Policy
- Automation
Core Technologies
- VXLAN
- LISP
- TrustSec
- Cisco DNA Center
Cisco SD-WAN
🌐 SD-WAN
Cisco SD-WAN provides centralized management and policy-driven control of enterprise WAN connections.
- MPLS
- Internet
- 4G/5G
- Application-aware routing
- Centralized policies
- Security
Benefits
- Centralized control
- Dynamic path selection
- Application visibility
- WAN optimization
- Security integration
CCNP Enterprise Practical Labs
Hands-on Cisco IOS practice
LAB 01 — VLAN & Trunk
vlan 10 name USERS interface gi0/1 switchport mode access switchport access vlan 10 interface gi0/24 switchport mode trunk
LAB 02 — STP
show spanning-tree show spanning-tree root show spanning-tree vlan 10
Identify the root bridge and understand port roles.
LAB 03 — EtherChannel
interface range gi0/1-2 channel-group 1 mode active show etherchannel summary
LAB 04 — EIGRP
router eigrp 100 network 10.0.0.0 0.0.0.255 show ip eigrp neighbors show ip eigrp topology
LAB 05 — EIGRP Stub
router eigrp 100 eigrp stub
LAB 06 — OSPF
router ospf 1 router-id 1.1.1.1 network 10.0.0.0 0.0.0.255 area 0 show ip ospf neighbor
LAB 07 — OSPF Stub Area
Create multiple OSPF areas and configure a stub area. Verify routes and LSDB behavior.
show ip ospf show ip ospf database
LAB 08 — OSPF Authentication
Configure authentication between OSPF neighbors and intentionally create an authentication mismatch for troubleshooting practice.
LAB 09 — EBGP
router bgp 65001 neighbor 192.0.2.2 remote-as 65002 show ip bgp summary
LAB 10 — IBGP
Build three routers in the same AS and configure IBGP. Study next-hop behavior and route propagation.
LAB 11 — BGP Path Selection
Change:
- Local Preference
- Weight
- AS Path
- MED
Observe how BGP selects the preferred path.
LAB 12 — Route Reflector
Create a route-reflector topology and compare it with a traditional full-mesh IBGP topology.
LAB 13 — Redistribution
Redistribute EIGRP into OSPF and OSPF into EIGRP. Use route maps and route tags to prevent loops.
LAB 14 — PBR
Configure two paths and use source-based policies to send selected traffic through different gateways.
LAB 15 — HSRP
interface gi0/0 standby 10 ip 192.168.10.1 standby 10 priority 110 standby 10 preempt
Shut down the active router and observe failover.
LAB 16 — NAT
Practice:
- Static NAT
- Dynamic NAT
- PAT
show ip nat translations show ip nat statistics
LAB 17 — VRF
Create Corporate and Guest VRFs and verify that their routing tables remain isolated.
show vrf show ip route vrf CORP
LAB 18 — GRE
Build a GRE tunnel between two routers and run a routing protocol across the tunnel.
LAB 19 — DMVPN
Build a hub-and-spoke topology using mGRE, NHRP, IPsec and dynamic routing.
LAB 20 — DHCP
ip dhcp pool USERS network 192.168.10.0 255.255.255.0 default-router 192.168.10.1 dns-server 8.8.8.8 show ip dhcp binding
LAB 21 — Wireless Troubleshooting
- Authentication failure
- Wrong VLAN
- DHCP failure
- Weak signal
- Roaming issue
- DNS problem
LAB 22 — MPLS L3 VPN
Build PE/P/CE topology and study VRF, RD, RT, MP-BGP and MPLS label forwarding.
LAB 23 — RESTCONF
Use a REST client or Python program to retrieve and modify network device data through RESTCONF.
LAB 24 — NETCONF
Use NETCONF and YANG to retrieve and configure structured network device information.
CCNP Troubleshooting
Analyze → Identify → Fix → Verify
🔍 General Troubleshooting Process
1. Identify the problem
↓
2. Collect information
↓
3. Identify possible causes
↓
4. Test the most likely cause
↓
5. Implement solution
↓
6. Verify
↓
7. Document
🧰 Essential Commands
show running-config show startup-config show interfaces show ip interface brief show ip route show ip protocols show cdp neighbors show lldp neighbors show logging show arp show mac address-table
🔀 Switching Troubleshooting
- Check VLAN membership.
- Check trunk configuration.
- Check STP.
- Check EtherChannel.
- Check MAC address learning.
🧭 Routing Troubleshooting
- Check routing table.
- Check neighbor relationships.
- Check route advertisements.
- Check metrics.
- Check route filtering.
- Check redistribution.
🌐 BGP Troubleshooting
- Check TCP/179 connectivity.
- Check AS number.
- Check neighbor state.
- Check route policy.
- Check next-hop reachability.
- Check BGP attributes.
📡 Wireless Troubleshooting
- Client association
- Authentication
- RF conditions
- VLAN
- DHCP
- IP connectivity
- DNS
- Roaming
🎯 CCNP Troubleshooting Mindset
Do not immediately change configurations. First understand the expected behavior, gather evidence, identify the failure domain, test a hypothesis and then make the smallest required change.
| Layer | Questions |
|---|---|
| Physical | Is the interface up? Cable? Optics? |
| Data Link | Correct VLAN? Trunk? STP? EtherChannel? |
| Network | Correct IP? Route? Routing protocol? |
| Transport | TCP/UDP? Ports? ACL? |
| Application | DNS? HTTP? Authentication? Application service? |
CCNP Enterprise Final Revision
What you should be able to explain
- Enterprise architecture
- VLAN and trunking
- CAM and CEF
- STP/RSTP/MST
- EtherChannel
- EIGRP
- OSPF
- OSPFv3
- Multiarea OSPF
- EBGP
- IBGP
- MP-BGP
- BGP path selection
- Route reflectors
- Redistribution
- PBR
- HSRP/VRRP
- NAT
- VRF
- GRE
- VTI
- DMVPN
- MPLS
- MPLS L3 VPN
- DHCP
- IPv6
- Multicast
- Wireless
- QoS
- Syslog
- Flexible NetFlow
- IP SLA
- EEM
- ACL
- AAA
- CoPP
- Python
- JSON
- APIs
- NETCONF
- RESTCONF
- DNA Center
- SD-Access
- SD-WAN
- Network automation