Thursday, February 9, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Networking

Innovation at the inner core of Cisco DNA Center

Researcher by Researcher
October 20, 2022
in Networking
0
Innovation at the inner core of Cisco DNA Center
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Cisco DNA Center has seen several releases with significant innovation and the evolution of the product platform. With DNA Center capabilities aligned to Gartner’s four IT personas (AIOps, NetOps, SecOps, and DevOps), it is important to take a step back and look at the platform or networks-put the “underlay.”

With changes in the IT landscape, several megatrends are shaping what the network platform needs to deliver. With the new landscape where both applications and users are on the move, the face of the campus network has changed and expanded.

Related articles

Massive ransomware operation targets VMware ESXi

Massive ransomware operation targets VMware ESXi

February 8, 2023
Harmonizing Networking and Security to Make SASE Easy

Harmonizing Networking and Security to Make SASE Easy

February 7, 2023

Megatrends shaping digital transformation
Figure 1. Megatrends shaping digital transformation


Cisco DNA Center Virtual Appliance, deployment flexibility

With applications moving to the cloud, it is no surprise that management platforms are moving to the cloud. Cisco DNA center is no exception. DNA Center is now able to run on AWS, and the deployment of the AWS VA takes under an hour from start to finish.   A lot of flexibility is also provided to the end user through the support of a launchpad to automate the installation or through a manual mode for users who already have a custom AWS environment. DNAC install is completely programmatic in both cases (no login to shell required!)

At this point, users can get on the Cisco DNA Center UI and begin configuration, discovery, and more.

Figure 2. Virtual Appliance Diagram


Following AWS, a VMWare version of the appliance will be released, allowing customers to use their existing VMWare infrastructure to run Cisco DNA Center instead of a physical appliance. As part of Cisco’s commitment to the platform, no matter how you deploy Cisco DNA Center, users will see feature parity it is the same Cisco DNA Center code and capabilities.

Hardened Security Features

Some verticals, industries, and organizations have specific security requirements mandated, such as FIPS.

Activation of FIPS compliance at Cisco DNA Center install time enables security features such as secure boot, TPM, session timeouts, and password expiration.  When data is shared using weak or deprecated ciphers, that data is at risk of being decrypted by malicious actors. Cisco DNA Center now supports FIPS 140-2-compliant cryptography modules, ensuring that only strong NIST-approved ciphers are used and enabling deployment in security-conscious verticals such as the public sector, finance, and healthcare.

Figure 3. FIPS compliance letter


ACL to management access for Cisco DNA Center appliance

By popular demand – many customers utilize ACL’s to control access to the network devices for management. As Cisco DNA Center is now the centralized monitoring and management point for network estate, customers can now create ACL’s to control what networks or IPs can access the Cisco DNA Center UI

Restricted shell support

Again by popular demand customers have requested to provide an enable shell for DNA Center so that sensitive CLI commands can be protected at all times. DNAC now comes with a restricted shell as standard and only non-invasive CLI is allowed to be run on the console. For any  CLI which requires root level / Sudo permissions, the shell will default deny it. A special token needs to be acquired to remove the restriction.

Scale – the agility to keep up with your business

Scale is a constant growth factor with post-pandemic life coming back to normal, with the proliferation of IoT and OT devices on the network on the rise. There is a constant need to ensure that the network management and orchestration platform can continue to scale with the network and business needs. With each release, Cisco DNA Center team has been making continuous strides with an increased platform scale. Recent scale updates for version 2.3.3 include up to 6,000 sites and 24,000 devices (Access Points and Network Devices for both Fabric and non-fabric networks).

DNA Scale
Figure 4. DNA Scale


Remote support

As part of improving the support engagement between customers and TAC, at times providing TAC easy access to the equipment has contributed to extending the MTTR (Mean time to repair). To ease the process, customers are now able to allow TAC access to network equipment via Cisco DNA Center. This solution enables the customer to provide TAC-specific access to equipment and the ability to revoke access at any time.

Remote Support Activation
Figure 5. Remote Support Activation


Aura (Audit & Upgrade Readiness Analyzer)

AURA stands for Audit & Upgrade Readiness Analyzer and performs various health, scale, and upgrade readiness checks for the Cisco DNA Center and the rest of the Fabric network. The tool is extremely simple to run and is executed on the Cisco DNA Center.

AURA screen image
Figure 6. AURA screen image

The tool uses API calls, DB reads and CLI show commands (read-only operations) and hence, doesn’t affect performance or cause impact the Cisco DNA Center or the networking devices. This functionality was built in collaboration with Cisco DNA Center Escalation Engineering, Sales, and CX Centers TAC Engines team to ensure an efficient upgrade experience. AURA Tool Check Areas:




  • DNA Center Scale Test
  • DNA Center Infra Health
  • DNA Center Assurance Health
  • WLC/eWLC Assurance Health
  • SDA Device CLI Capture
  • SDA Control & Security Audit
  • Software Bugs Causing Upgrade Failures
  • Upgrade Readiness Checks
  • SDA Compatibility Check (Switches, Wireless Controllers & ISE for 2.2.2.x)
  • DNAC-ISE Integration Checks
  • Fabric Devices Configurations Capture and Compare using inbuilt diff tool

System Analyzer screen image
Figure 7. System Analyzer screen image


 

Visit Cisco DNA Center web page for additional resources and information

Additional Resources:

Cisco dCloud to experience and demo Cisco DNA Center via your Cisco log-in credentials

Cisco DNA Center Communities to connect with your peers and Cisco specialists

* Gartner “Market Guide for Network Automation Tools” Published 22 February 2022 – ID G00735443

Share:



Source link

Tags: CenterCiscocoreDNAInnovation
Share76Tweet47

Related Posts

Massive ransomware operation targets VMware ESXi

Massive ransomware operation targets VMware ESXi

February 8, 2023
0

These ransomware infections on VMware ESXi software are due to a vulnerability that has existed since 2021. Find out the...

Harmonizing Networking and Security to Make SASE Easy

Harmonizing Networking and Security to Make SASE Easy

February 7, 2023
0

In an era where the experience is everything, digital transformation can be hard for IT organizations, creating increased operational complexity....

Cisco Catalyst 9200CX now orderable!

New Cisco Catalyst 9200CX Compact With HVDC, Cisco UPOE And mGig

February 6, 2023
0

Figure 1. Cisco Live Amsterdam 2023 Make sure your network is ready for a hybrid world where the workplace is...

Cisco Catalyst 9000 Core Switches: Don’t Let Your Core Stop Turning

Cisco Catalyst 9000 Core Switches: Don’t Let Your Core Stop Turning

February 2, 2023
0

There have been a lot of talks recently about the article entitled “Multidecadal variation of the Earth’s inner-core rotation”. The...

Attend Cisco Live: Build Unified Experiences Using Simplicity And Data Intelligence

Attend Cisco Live: Build Unified Experiences Using Simplicity And Data Intelligence

February 1, 2023
0

I’m excited to pack my bags to attend Cisco Live EMEA in Amsterdam next week! After a three-year hiatus, two words...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Google’s AI Chatbot Is Out To Rival ChatGPT

Google’s AI Chatbot Is Out To Rival ChatGPT

February 9, 2023
New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023
“Fintech Right Now is a Boys Club” – How to Close the Gender Gap in Fintech with Stax

Spotlight: How the Isle of Man Became an Insurtech Hub

February 8, 2023

Recent Posts

Google’s AI Chatbot Is Out To Rival ChatGPT

Google’s AI Chatbot Is Out To Rival ChatGPT

February 9, 2023
New cybersecurity data reveals persistent social engineering vulnerabilities

New cybersecurity data reveals persistent social engineering vulnerabilities

February 9, 2023
New ToddyCat APT Targets Exchange Servers

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

February 8, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved