2.3 SD-Access Campus Interoperability: Integrating Traditional Networks with Fabric

Key Takeaways

  • Phased migration from traditional campus networks to Cisco SD-Access relies on Layer 2 and Layer 3 border handoffs to maintain connectivity, addressing, and default gateways.

  • Layer 2 Border handoffs extend legacy VLANs across the fabric boundary for temporary brownfield transitions, but carry Spanning Tree dependencies and scale limitations.

  • Layer 3 Border handoffs map fabric Virtual Networks (VNs) to VRF-Lite instances over routed subinterfaces with dynamic routing (eBGP or OSPF), providing high scalability and Layer 2 fault isolation.

  • Cisco TrustSec Security Group Tag Exchange Protocol (SXP) propagates SGT-to-IP binding tables over TCP port 64999 to legacy switches and firewalls that lack native VXLAN-GPO hardware support.

  • Shared enterprise services (DHCP, DNS, ISE, Active Directory) can be accessed across segregated Virtual Networks using fusion router route leaking, border node leaking, or firewall transit inspection.

Last updated: October 2026

SD-Access Campus Interoperability: Integrating Traditional Networks with Fabric

Enterprise campus networks rarely transition to modern software-defined fabrics overnight. Migration occurs incrementally: individual buildings, floors, or wiring closets transition from traditional multi-tier Layer 2/Layer 3 architectures to Cisco SD-Access. During this migration, the SD-Access fabric must interoperate with legacy 802.1Q VLAN trunks, Spanning Tree domains, external firewalls, wireless controllers, and enterprise shared services.

Achieving seamless interoperability requires robust boundary handoffs that preserve network segmentation, maintain policy continuity, and provide uninterrupted client connectivity.

Interoperability Models: Layer 2 vs. Layer 3 Border Handoffs

The Fabric Border Node serves as the architectural demarcation point connecting the SD-Access fabric to traditional networks. Depending on migration requirements, engineers implement Layer 2 or Layer 3 handoffs:

ParameterLayer 2 Border HandoffLayer 3 Border Handoff
Primary PurposePhased brownfield migration; stretching legacy VLANs across the fabric boundary.Permanent enterprise connection; linking fabric overlays to traditional core, WAN, and DC.
Default GatewayLocated on external legacy distribution or core switches.Located on Fabric Edge nodes (Anycast Gateway) or external Layer 3 routers.
Subnet ScopeSingle IP subnet spans across both fabric and legacy switches simultaneously.Subnets are strictly contained either within the fabric or outside.
Broadcast HandlingBroadcast and unknown unicast frames traverse the border into the fabric.Broadcast domains terminate at the border; clean Layer 3 routed boundary.
Spanning Tree (STP)STP BPDUs pass across the border; requires careful STP guard configuration.Zero STP interaction; STP BPDUs are blocked at the routed interface.
Design LongevityTemporary transition mechanism; decommissioned after endpoint migration.Permanent, scalable architectural standard for enterprise production.

Layer 2 Border Handoff Implementation

During early migration phases, renumbering IP addresses on thousands of static endpoints (such as medical devices or printers) is often impractical. A Layer 2 Border Handoff allows endpoints on an existing VLAN to be moved to a Fabric Edge switch while retaining their original IP addresses and keeping their default gateway on the traditional core:

  • The Fabric Border functions as a bridging node, connecting to the legacy switch over an 802.1Q trunk.
  • When a migrated host in the fabric communicates with its default gateway on the legacy core, the Fabric Edge encapsulates the frame in VXLAN and sends it to the L2 Border, which decapsulates it and places it on the 802.1Q trunk.
  • Precautions: Because Layer 2 handoffs extend broadcast domains, administrators must configure spanning-tree bpdufilter or bpduguard selectively to prevent legacy STP Topology Change Notifications (TCNs) from causing widespread MAC flushing. Once all endpoints in a subnet are migrated, the gateway is moved to the Fabric Anycast Gateway and the Layer 2 handoff is removed.

Layer 3 Border Handoff Implementation

A Layer 3 Border Handoff provides a permanent, scalable connection:

  • The Fabric Border terminates fabric VXLAN encapsulation and connects to an external Fusion Router or Core Switch over routed point-to-point links.
  • Macro-segmentation is preserved using VRF-Lite: each Virtual Network (VN) in the fabric maps directly to an 802.1Q subinterface and corresponding VRF on the external device.
  • Routing Protocols: Exterior BGP (eBGP) is preferred between the Fabric Border and the Fusion Router due to granular prefix filtering, independent autonomous system numbers, and BGP community controls; Multi-Area OSPFv2/OSPFv3 is also supported with separate OSPF processes per VRF.

Policy Continuity: Cisco TrustSec SXP

Inside the fabric, micro-segmentation is maintained by carrying the 16-bit Security Group Tag (SGT) inside the VXLAN-GPO header. However, when traffic exits the fabric over a Layer 3 VRF-Lite handoff, the border strips the VXLAN header, converting packets to standard IP frames.

Because legacy switches, data center switches, and firewalls often lack hardware support for inline SGT tagging (Cisco Meta Data, optionally protected by MACsec), security policy context is lost unless an out-of-band protocol is used.

SGT Exchange Protocol (SXP) Architecture

Cisco TrustSec SGT Exchange Protocol (SXP), published as an IETF informational draft rather than an RFC, transports IP-to-SGT binding tables across network devices lacking inline tagging capability:

  • Transport: SXP establishes a peering session over TCP port 64999, authenticated with MD5 passwords.
  • Roles: The Fabric Border Node (or Cisco ISE) acts as an SXP Speaker, sending IP-to-SGT bindings. Legacy switches or firewalls act as SXP Listeners, receiving the mappings and populating local hardware tables.
  • Policy Enforcement: When an untagged packet reaches the legacy firewall, the firewall references its SXP table, matches the source IP to its SGT, and enforces role-based Security Group ACLs (SGACLs).

Shared Services Access Architectures

Enterprise infrastructure services (Active Directory, DNS, DHCP, ISE, NTP) must be reachable by endpoints in isolated Virtual Networks (e.g., Users, IoT, Guests).

Engineers use three primary architectures to provide access across VRF boundaries:

  1. Fusion Router Route Leaking: The Fabric Border hands off VNs to an external Fusion Router via VRF-Lite. The Fusion Router maintains client VRFs alongside a dedicated Shared_Services VRF, using MP-BGP route-target import/export rules to leak shared service prefixes into client VRFs and client subnets back to shared services.
  2. Border Node Local Leaking: High-capacity border platforms (Catalyst 9500/9600) can leak routes between VRFs directly on the border switch using route-target import/export, eliminating separate fusion hardware.
  3. Firewall Transit Inspection: VNs connect via VRF-Lite to distinct zones on a Next-Generation Firewall. The firewall statefully inspects all inter-VN and shared services traffic, preventing lateral movement from compromised endpoints.

Wireless Integration: Fabric-Enabled vs. Over-the-Top (OTT)

Wireless configuration is no longer an ENCOR v1.2 topic, but you still need to recognize how wireless traffic relates to the SD-Access fabric.

Over-the-Top (OTT) Wireless

  • APs connect to Fabric Edge ports configured as standard access ports and build CAPWAP tunnels to a centralized Wireless LAN Controller (WLC).
  • Both control signaling and client user data travel inside CAPWAP. The fabric treats CAPWAP packets as opaque IP traffic.
  • User traffic hairpins back to the central WLC, creating latency and throughput bottlenecks.

Fabric-Enabled Wireless (FEW)

  • Split Architecture: APs form a CAPWAP control tunnel to the WLC for radio management and client authentication, but user data is handled locally.
  • Distributed Data Plane: The fabric AP encapsulates client traffic in VXLAN toward the fabric edge switch it connects to, and the edge forwards it across the fabric overlay like wired traffic.
  • Unified Policy & Anycast Gateway: Wireless clients use the same Anycast Layer 3 Gateway on the Fabric Edge as wired devices. Roaming between APs updates LISP EID-to-RLOC mappings without changing IP addresses or hair-pinning traffic.

Troubleshooting Interoperability

  • SXP Peering: Check TCP port 64999 connectivity, MD5 authentication, and version negotiation (SXPv4 recommended) using show cts sxp connections and show cts sxp sgt-map.
  • Border MTU Verification: Ensure subinterface MTUs match external fusion router ports. While underlay links use MTU ≥ 9100, traditional IP links default to 1500 bytes.
  • Asymmetric Inter-VRF Routing: Verify that return routes for shared services are symmetrically leaked. Route leaks that bypass stateful firewalls cause drops due to state violations.
  • STP Containment: Use spanning-tree bpdufilter enable on L2 border handoff interfaces where appropriate to prevent legacy STP TCNs from triggering MAC flushing in the fabric.
Test Your Knowledge

In an enterprise migrating from a traditional campus to Cisco SD-Access, why is a Layer 3 Border handoff using VRF-Lite preferred over a Layer 2 Border handoff for permanent interconnection?

A

Layer 3 handoffs stretch broadcast domains across both legacy and fabric switches to simplify DHCP snooping.

B

Layer 3 handoffs require fewer physical cables by encapsulating all traffic inside proprietary IS-IS tunnels.

C

Layer 3 handoffs establish a clean routed boundary that isolates Spanning Tree loops and terminates broadcast domains while scaling multi-tenant VRFs.

D

Layer 3 handoffs allow legacy access switches to participate directly in LISP Map-Server registration without hardware upgrades.

Test Your Knowledge

What role does the Cisco TrustSec SXP (Security Group Tag Exchange Protocol) perform when interconnecting an SD-Access fabric with traditional infrastructure?

A

It sends IP-to-SGT bindings over TCP to legacy switches and firewalls that cannot read inline VXLAN-GPO tags.

B

It dynamically discovers and provisions intermediate P routers in the routed underlay using IS-IS link-state packets.

C

It acts as an external authoritative DNS server to resolve hostname queries for endpoints in isolated Virtual Networks.

D

It encrypts Layer 2 frames with 256-bit AES MACsec encryption across point-to-point fiber connections.

Test Your Knowledge

In a Cisco Fabric-Enabled Wireless (FEW) deployment within SD-Access, how is wireless client user data forwarded?

A

Encapsulated inside CAPWAP data tunnels and switched centrally by the Wireless LAN Controller (WLC), exactly as in over-the-top designs

B

Transmitted in unencrypted cleartext across intermediate underlay P routers directly to the Internet

C

Bridged into a dedicated management VLAN and routed through an external SXP speaker switch

D

Encapsulated in VXLAN by the fabric AP toward its fabric edge and forwarded over the fabric overlay, bypassing the WLC data path

Sections you finish are checked off in the contents.