2.2 Cisco SD-Access Architecture: Control Plane, Data Plane, and Fabric Node Roles

Key Takeaways

  • Cisco Software-Defined Access (SD-Access) separates the campus network into an automated, non-blocking Layer 3 routed Underlay and a virtualized multi-tenant Overlay.

  • The SD-Access Control Plane implements Locator/ID Separation Protocol (LISP) to decouple host identity (Endpoint Identifier - EID) from its current network location (Routing Locator - RLOC), eliminating broadcast ARP flooding.

  • The SD-Access Data Plane utilizes Virtual Extensible LAN (VXLAN) encapsulation with Group-Based Policy extensions (VXLAN-GPO), carrying a 16-bit Security Group Tag (SGT) inside the VXLAN header.

  • Fabric node roles provide specialized functions: Fabric Edge Nodes onboard endpoints and perform VXLAN encapsulation; Fabric Border Nodes bridge fabric traffic to external networks; Fabric Control Plane Nodes maintain the central LISP Map-Server/Map-Resolver database.

  • Intermediate Nodes in the underlay act as standard IP transit routers with no fabric state; Cisco recommends a 9100-byte underlay MTU so the 50 bytes of VXLAN-GPO overhead never forces fragmentation.

Last updated: October 2026

Cisco SD-Access Architecture: Control Plane, Data Plane, and Fabric Node Roles

Enterprise campus networks historically relied on hierarchical models with Layer 2 Spanning Tree Protocol (STP) domains spanning access and distribution layers. These designs suffered from blocked links, complex multi-chassis EtherChannel workarounds, broadcast flooding, and rigid VLAN-to-subnet bindings that restricted mobility. Securing endpoints required complex manual IP-based Access Control Lists (ACLs).

Cisco Software-Defined Access (SD-Access) resolves these limitations by introducing a programmable campus fabric that decouples network services from physical infrastructure, pairing an automated routed underlay with a virtualized overlay to deliver uniform policy, automated segmentation, and seamless mobility.

Underlay vs. Overlay Architecture

SD-Access establishes a strict separation between physical transport and virtualized network services:

+--------------------------------------------------------------+
|                         OVERLAY                              |
|   Virtual Networks (VRFs) + Group-Based Policy (SGTs)        |
|   Data Plane: VXLAN-GPO  |  Control Plane: LISP              |
+--------------------------------------------------------------+
                               |
               (Encapsulated across Underlay)
                               v
+--------------------------------------------------------------+
|                         UNDERLAY                             |
|   Physical Switches, Routers, and Point-to-Point Links       |
|   Layer 3 Routed Fabric (IS-IS / OSPF) with MTU >= 9100      |
+--------------------------------------------------------------+

The Routed Underlay

The underlay comprises the physical switches, routers, and cabling providing base IP connectivity:

  • Layer 3 Routed Fabric: Spanning Tree is eliminated from the core and distribution layers. Every link between access and distribution switches operates as a routed point-to-point Layer 3 connection.
  • Equal-Cost Multi-Pathing (ECMP): With Layer 3 routed interfaces, all physical links actively forward traffic simultaneously, delivering deterministic sub-second convergence.
  • Routing Protocol: Intermediate System to Intermediate System (IS-IS) is standard and automatically deployed by Cisco Catalyst Center LAN Automation; routed OSPF is also supported.
  • Underlay MTU: Cisco recommends a 9100-byte jumbo MTU on underlay links, and LAN Automation configures it. At a minimum, every link must carry the largest client frame plus the 50 bytes of VXLAN-GPO overhead, so a 1500-byte client packet needs at least 1550 bytes.

The Virtualized Overlay

The overlay is the virtualized network operating over the underlay:

  • Macro-Segmentation: Implemented via Virtual Networks (VNs) using Virtual Routing and Forwarding (VRF) instances to isolate distinct user groups (e.g., Corporate, IoT, Guests).
  • Micro-Segmentation: Granular security enforced within each VN using Cisco TrustSec Security Group Tags (SGTs). Policies apply to endpoints regardless of IP address or switch port.

Control Plane Architecture: Locator/ID Separation Protocol (LISP)

Traditional routing conflates identity (who a device is) with location (where it connects). SD-Access uses Locator/ID Separation Protocol (LISP; originally RFC 6830, now RFC 9300 and RFC 9301) to split the IP address into two namespaces:

  1. Endpoint Identifier (EID): The IP or MAC address assigned to an end host. The EID represents host identity and remains static when roaming.
  2. Routing Locator (RLOC): The Layer 3 underlay loopback IP address of the Fabric Edge switch to which the host attaches. The RLOC represents location and is routable in the underlay.

LISP Control Plane Components

LISP RoleFunction in SD-Access Fabric
Map-Server (MS)Receives Map-Register messages from Fabric Edge nodes when endpoints connect; maintains the central authoritative EID-to-RLOC database.
Map-Resolver (MR)Receives Map-Request queries from Fabric Edge nodes searching for the destination RLOC for a target EID; responds with a Map-Reply.
Control Plane NodeDedicated or collocated fabric switch running the centralized LISP MS/MR database services.
[Host A (EID_A)] ---> [Edge 1 (RLOC_1)] ---------------------> [Edge 2 (RLOC_2)] ---> [Host B (EID_B)]
                            |                                        ^
                   (1) Map-Request (EID_B?)                 (2) Map-Reply (EID_B is at RLOC_2)
                            v                                        |
                   +-------------------------------------------------+
                   |           Fabric Control Plane Node             |
                   |               (LISP MS / MR)                    |
                   +-------------------------------------------------+

Eliminating Broadcast Flooding

Instead of broadcasting ARP requests across all switches in a VLAN, the Fabric Edge intercepts host ARP requests, queries the Control Plane Node with a unicast LISP Map-Request, receives the target switch's RLOC, and forwards traffic directly via unicast VXLAN.

Data Plane Encapsulation: VXLAN-GPO

SD-Access uses Virtual Extensible LAN with Group-Based Policy (VXLAN-GPO) for data forwarding. Standard VXLAN (RFC 7348) encapsulates Layer 2 frames in UDP (port 4789) with a 24-bit VXLAN Network Identifier (VNI). VXLAN-GPO modifies the 8-byte VXLAN header to carry a 16-bit Group Policy ID (Security Group Tag / SGT).

VXLAN-GPO Header Breakdown

LayerHeader ComponentSizeFunction
Outer Layer 2Outer Ethernet Header14 BytesNext-hop physical switch MAC addresses across underlay hops.
Outer Layer 3Outer IPv4 Header20 BytesSource RLOC (ingress edge) and Destination RLOC (egress edge).
Outer Layer 4Outer UDP Header8 BytesDest port 4789; source port is a hash of inner packet for ECMP entropy.
Overlay HeaderVXLAN-GPO Header8 BytesContains G flag, 16-bit SGT, and 24-bit VNI (Virtual Network).
Inner PayloadOriginal Client FrameVariableOriginal Ethernet frame (Source/Dest MAC, IP, TCP/UDP, and data).

Total encapsulation overhead is 50 bytes, allowing policy (SGT) and multi-tenancy (VNI) to travel inline with every packet.

Fabric Node Roles

An SD-Access fabric organizes devices into distinct functional roles:

Fabric Node RolePlacementPrimary Responsibilities
Fabric Edge NodeCampus Access Layer (e.g., Catalyst 9300)Onboards and authenticates endpoints (802.1X, MAB, WebAuth); maps endpoints to VLANs, VNIs, and SGTs; acts as Anycast Layer 3 Gateway; registers local EIDs with Control Plane; encapsulates egress frames into VXLAN-GPO; decapsulates ingress VXLAN frames and enforces SGACLs.
Fabric Control Plane NodeCampus Core/Distribution (e.g., Catalyst 9500)Runs the LISP Map-Server and Map-Resolver; maintains the EID-to-RLOC database; tracks host mobility events across the campus.
Fabric Border NodeCampus Core/Edge (e.g., Catalyst 9500/9600)Connects the fabric overlay to external networks (WAN, Internet, traditional campus); translates LISP/VXLAN state to external routing protocols (eBGP, OSPF, VRF-Lite).
Intermediate NodeCampus Spine/Core (e.g., Catalyst 9500)Standard Layer 3 underlay router (P router); forwards packets using outer IP headers; unaware of VXLAN, LISP, or SGTs; requires jumbo MTU (9100 bytes recommended).
Fabric Extended NodeWiring Closets / Industrial (e.g., Catalyst IE3300)Layer 2 switch connected downstream to a Fabric Edge; extends segmentation to peripheral ports via 802.1Q without terminating VXLAN.

Border Node Classifications

  • Internal Border: Connects to corporate data centers and internal services; advertises fabric subnets out and imports enterprise routes.
  • External Border: Connects to uncontrolled external networks (Internet/Cloud); originates and advertises a default route (0.0.0.0/0) into the fabric.
  • Anywhere Border: Combines internal and external border responsibilities on a single platform.

Centralized Orchestration: Catalyst Center and ISE

  • Cisco Catalyst Center (formerly DNA Center): Central automation and assurance engine. Manages LAN Automation (PnP underlay provisioning via IS-IS), fabric design, and telemetry assurance.
  • Cisco Identity Services Engine (ISE): Integrates via pxGrid to authenticate endpoints, evaluate posture, assign SGTs dynamically, and propagate security matrices to fabric nodes.
Test Your Knowledge

In the Cisco SD-Access control plane, what role does the Locator/ID Separation Protocol (LISP) Map-Server (MS) perform?

A

It encapsulates outgoing Layer 2 Ethernet frames into outer UDP packets addressed to the remote destination switch's RLOC.

B

It dynamically assigns IP addresses to connected client workstations through DHCP discover and offer exchanges.

C

It inspects packet payloads to evaluate deep packet inspection security rules and intrusion detection signatures.

D

It receives Map-Register messages from fabric edge nodes and stores each endpoint's EID-to-RLOC mapping for the fabric.

Test Your Knowledge

What unique enhancement does the Cisco VXLAN-GPO header provide over standard RFC 7348 VXLAN in an SD-Access fabric?

A

It increases the size of the VXLAN Network Identifier (VNI) from 24 bits to 32 bits to expand total subnet scale.

B

It carries a 16-bit Security Group Tag (SGT) in the 8-byte VXLAN header, so policy travels with each packet.

C

It substitutes TCP for UDP at Layer 4 to guarantee reliable end-to-end delivery of every fabric packet without any drops.

D

It eliminates the outer IP header entirely to compress packet size down to standard 1500-byte MTU limits.

Test Your Knowledge

Which type of Cisco SD-Access Fabric Border Node is responsible for connecting the fabric to uncontrolled external networks, typically advertising a default route into the fabric?

A

Internal Border Node

B

Intermediate Transit Node

C

External Border Node

D

Extended Access Node

Sections you finish are checked off in the contents.