Exam 350-401 | Comprehensive Study Guide with Labs & Quiz
15% of Exam Weight
๐ Section 1.0 Architecture โ Exam Overview
Section 1.0 Architecture accounts for 15% of the CCNP ENCOR 350-401 v1.2 exam. It tests your ability to explain, analyze, and differentiate enterprise network design models, wireless deployments, cloud vs on-premises infrastructure, SD-WAN, SD-Access, and hardware/software forwarding mechanisms.
15% โ Architecture (this section)
| Sub-topic | Topic |
|---|---|
| 1.1 | Enterprise network design principles (Tier 2/3, Fabric, HA) |
| 1.2 | WLAN deployment design (models, location services) |
| 1.3 | On-premises vs cloud infrastructure |
| 1.4 | Cisco SD-WAN solution (control/data planes) |
| 1.5 | Cisco SD-Access solution (fabric, LISP, VXLAN) |
| 1.6 | Hardware/software switching: CEF, CAM, TCAM, FIB, RIB |
1.1 โ Enterprise Network Design Principles
Cisco’s enterprise network design follows a hierarchical model that simplifies management, improves scalability, and increases fault tolerance. The three fundamental design approaches are the Three-Tier, Two-Tier (Collapsed Core), and Spine-Leaf (Fabric) architectures.
1.1.a โ Tier 2, Tier 3, and Fabric Capacity Planning
Three-Tier (Tier 3) Architecture
The classic enterprise design separates the network into three distinct layers, each with a specific role:
- Access Layer โ Connects end devices (PCs, phones, APs). Enforces QoS, port security, and VLAN assignment.
- Distribution Layer โ Aggregates access switches. Handles inter-VLAN routing, policy enforcement, and redundant uplinks to the core.
- Core Layer โ High-speed backbone. Switches packets as fast as possible. No policy enforcement here.
Figure 1 โ Three-Tier (Tier 3) Hierarchical Campus Architecture
Two-Tier (Collapsed Core) Architecture
The Two-Tier design merges the Core and Distribution layers into a single layer โ ideal for medium-sized campuses (typically fewer than 200 switches). Benefits include reduced cost and simpler management.
Figure 2 โ Two-Tier (Collapsed Core) Architecture
Spine-Leaf (Fabric) Architecture
Originally from data centers, the Spine-Leaf topology provides predictable latency and non-blocking bandwidth. Every Leaf switch connects to every Spine switch (full mesh at the spine layer). There are no Leaf-to-Leaf connections. Used in modern campus deployments with SD-Access.
- Spine โ Layer 3 routing fabric backbone. Typically 2โ4 spine switches for redundancy.
- Leaf โ Layer 2/3 edge. Connects to servers, endpoints, or other Leaf switches via Spine.
- Maximum hop count from any Leaf to Leaf = 2 hops (Leaf → Spine → Leaf). Each leaf-to-spine link is one hop, so every leaf sits exactly two hops from every other leaf.
Figure 3 โ Spine-Leaf Fabric Architecture
Capacity Planning Considerations
| Factor | Tier 3 | Tier 2 (Collapsed) | Spine-Leaf |
|---|---|---|---|
| Scale | Large enterprise | Medium campus | Data center / large campus |
| Latency | Variable (more hops) | Low-moderate | Consistent (always 2 hops) |
| Redundancy | High | Moderate | Very high |
| Cost | High | Low-moderate | High |
| STP dependency | Yes (access/dist) | Yes | No (L3 fabric) |
| East-West traffic | Poor | Moderate | Excellent |
1.1.b โ High Availability: Redundancy, FHRP & SSO
First Hop Redundancy Protocols (FHRP)
FHRPs provide default gateway redundancy so end devices never lose connectivity when a router fails.
| Protocol | Standard | Virtual IP Ownership | Preemption | Load Balancing |
|---|---|---|---|---|
| HSRP v1/v2 | Cisco proprietary | Active router | Optional (off by default) | Per-group only |
| VRRP | IEEE 802.1 (open) | Master router | Preempt on by default | Per-group only |
| GLBP | Cisco proprietary | AVG assigns multiple AVFs | Optional | True per-host LB |
Figure 4 โ HSRP/VRRP Active-Standby Default Gateway Redundancy
Stateful Switchover (SSO) & Non-Stop Forwarding (NSF)
- SSO โ On dual-supervisor routers/switches, the standby supervisor stays synchronized with the active one. On failover, switching continues with zero packet loss.
- NSF (Graceful Restart) โ Routing protocol peers are notified of the RP failover and continue forwarding traffic while the routing table rebuilds. Supported by OSPF, IS-IS, EIGRP, BGP.
- NSR (Non-Stop Routing) โ The standby RP maintains its own routing state. No neighbor awareness needed โ fully transparent to peers.
- BFD โ Bidirectional Forwarding Detection. Sub-second failure detection for any routing protocol.
| Technology | What it does | Peer awareness needed? |
|---|---|---|
| SSO | Synchronizes supervisor state for instant failover | No |
| NSF/GR | Signals routing peers to hold routes during restart | Yes |
| NSR | Standby RP maintains full routing state | No |
| BFD | Sub-second link/path failure detection | Yes (both ends) |
1.2 โ WLAN Deployment Design
1.2.a โ Wireless Deployment Models
Cisco supports six wireless deployment models. Choosing the right one depends on network size, management complexity, location services requirements, and bandwidth.
Centralized
WLC in data center. All AP traffic tunneled back via CAPWAP. Best for campuses needing centralized policy and visibility.
Distributed / FlexConnect
APs switch traffic locally. WAN failure resilient. Ideal for branch offices with low-bandwidth WAN links.
Controller-Less (Autonomous)
Each AP self-managed. No WLC needed. Simple for very small deployments but no roaming or central policy.
Controller-Based
Dedicated physical WLC. APs are “lightweight” (LAP). Standard enterprise model โ central management, roaming, RF management.
Cloud-Managed (Meraki/DNA)
WLC function hosted in cloud. Zero-touch provisioning. Cisco Meraki or Catalyst Center (DNA Center) in cloud.
Remote Branch (EWC)
Embedded Wireless Controller in an AP or switch. No separate WLC hardware needed at branch. Catalyst 9100 APs support EWC.
Figure 5 โ Wireless Deployment Models Compared
CAPWAP Protocol
Control And Provisioning of Wireless Access Points (CAPWAP) is the tunneling protocol between APs and WLC. It uses two channels:
- Control channel (UDP 5246) โ DTLS-encrypted management traffic (AP join, config, keepalive)
- Data channel (UDP 5247) โ Optionally encrypted user data traffic
1.2.b โ Location Services in WLAN Design
Cisco CMX (Connected Mobile Experiences) and DNA Spaces provide location services using these methods:
| Method | Technology | Accuracy |
|---|---|---|
| RSSI Triangulation | Multiple APs measure signal strength | ~10โ15 metres |
| FastLocate / AOA | Angle of Arrival (Wi-Fi 6E) | ~1โ3 metres |
| BLE Beacon | Bluetooth Low Energy tags | ~2โ5 metres |
| Ultra-Wideband (UWB) | Cisco Ultra-Wideband tag | <1 metre |
1.3 โ On-Premises vs Cloud Infrastructure
On-Premises
- Hardware & software owned and managed by the organization
- Full control over data, compliance, and security posture
- High CapEx (capital expenditure)
- Longer deployment time
- Examples: Cisco Catalyst switches, on-prem DNA Center appliance
Cloud Infrastructure
- Resources delivered as-a-service (IaaS, PaaS, SaaS)
- OpEx model โ pay per use
- Rapid elasticity and scalability
- Shared responsibility model for security
- Examples: Cisco Meraki (cloud WLC), Catalyst Center SaaS, AWS/Azure VPC
Cloud Service Models Relevant to ENCOR
| Model | Managed By Customer | Managed By Provider | Example |
|---|---|---|---|
| IaaS | OS, Apps, Data, Runtime | Hypervisor, Servers, Storage, Network | AWS EC2, Azure VMs |
| PaaS | Applications, Data | OS, Runtime, Middleware, Infrastructure | Heroku, Azure App Service |
| SaaS | Data (partially) | Everything else | Webex, Salesforce, Meraki |
Hybrid and Multi-Cloud
Enterprise networks increasingly use hybrid cloud (mix of on-prem + cloud) or multi-cloud (multiple cloud providers). Cisco SD-WAN and Cisco+ (Networking Cloud) provide consistent connectivity and policy across all environments.
1.4 โ Cisco SD-WAN Solution
Cisco SD-WAN (formerly Viptela) decouples the WAN control plane from the data plane, enabling centralized policy, automated provisioning, and application-aware routing across any transport (MPLS, broadband, 4G/5G, satellite).
SD-WAN Architecture Components
Figure 6 โ Cisco SD-WAN Architecture (Viptela / IOS-XE SD-WAN)
SD-WAN Component Roles
| Component | Plane | Function | Protocol Used |
|---|---|---|---|
| vManage | Management | Central GUI, REST API, configuration templates, monitoring | HTTPS / NetConf / RESTCONF |
| vBond | Orchestration | First point of contact; authenticates all devices; assists NAT traversal; requires public IP | DTLS/TLS |
| vSmart | Control | Distributes routing & policy via OMP; acts as route reflector to all vEdge/cEdge | OMP over TLS |
| vEdge / cEdge | Data | Physical/virtual WAN edge router; builds IPsec tunnels between sites; enforces app-aware policy | IPsec / OMP |
1.4.b โ Traditional WAN vs SD-WAN
| Attribute | Traditional WAN | SD-WAN |
|---|---|---|
| Transport | MPLS only (or limited) | Any transport (MPLS, broadband, LTE, satellite) |
| Configuration | CLI per-device | Centralized templates via vManage |
| Routing | OSPF/BGP/EIGRP per device | OMP centrally reflects routes |
| Application visibility | Limited (DPI optional) | Built-in DPI & app-aware routing |
| Security | Perimeter-only | Built-in IPsec, cloud security integration (Zscaler, Umbrella) |
| ZTP (Zero-Touch) | No | Yes โ plug in, contacts vBond, auto-provisions |
1.5 โ Cisco SD-Access Solution
SD-Access is Cisco’s campus fabric solution, managed by Cisco Catalyst Center (formerly DNA Center). It automates campus network provisioning, segmentation, and policy enforcement using an underlay/overlay model.
SD-Access Layered Architecture
Figure 7 โ SD-Access Architecture: Underlay / Overlay / Management Planes
1.5.a โ SD-Access Control and Data Plane
| Plane | Protocol | Function |
|---|---|---|
| Control Plane | LISP (Locator/ID Separation Protocol) | Maps endpoint identities (EID) to RLOC (routing locator/VTEP IP). Handles mobility and any-to-any policy. |
| Data Plane | VXLAN (Virtual Extensible LAN) | MAC-in-UDP encapsulation. Carries original Ethernet frame including 802.1Q VLAN tag. Adds SGT header for policy. |
| Policy Plane | Cisco TrustSec / SGT | Scalable Group Tags embedded in VXLAN header. Identity-based micro-segmentation without complex ACLs. |
| Management Plane | NETCONF / RESTCONF | Catalyst Center programs all fabric nodes via API (Intent-Based Networking). |
Why LISP for the Control Plane?
- Traditional routing ties who you are (IP address) to where you are (location on the network).
- LISP separates the EID (Endpoint ID โ your IP address) from the RLOC (Routing Locator โ the VTEP/edge node loopback).
- When a client moves, only the LISP map updates โ no re-IP, no spanning tree convergence.
Why VXLAN for the Data Plane?
- Extends Layer 2 across a Layer 3 underlay using MAC-in-UDP encapsulation (UDP port 4789).
- 24-bit VNID (Virtual Network Identifier) โ supports 16 million virtual networks vs VLAN’s 4094.
- Carries the original Ethernet frame including 802.1Q VLAN and SGT for policy enforcement.
1.5.b โ Traditional Campus Interoperating with SD-Access
Not all campus areas can be migrated to SD-Access at once. The Border Node bridges between the fabric and legacy/external networks:
- Default Border โ Handles traffic to unknown destinations (exits fabric to external routing domain).
- External Border โ Connects to known external networks (e.g., data center, internet, legacy campus).
- Traditional OSPF/BGP routes are redistributed into LISP by the border node.
1.6 โ Hardware & Software Switching Mechanisms
Understanding how a router/switch makes forwarding decisions requires knowledge of multiple tables and their interaction.
The Forwarding Pipeline
Figure 8 โ L3 CEF Forwarding Pipeline
Key Tables Explained
| Table / Structure | Layer | Contents | Location |
|---|---|---|---|
| RIB (Routing Information Base) | L3 | All routes from all protocols. Best routes selected per prefix and installed into FIB. | Software (RAM) |
| FIB (Forwarding Information Base) | L3 | CEF-optimized copy of best routes from RIB. Used for packet forwarding decisions. Updated by CEF from RIB. | Hardware TCAM |
| Adjacency Table | L2/L3 | Next-hop IP โ outgoing interface + Layer 2 rewrite info (dest MAC, src MAC, VLAN). Populated from ARP/ND. | Hardware |
| CAM (Content Addressable Memory) | L2 | MAC address table: MAC โ port mapping. Exact-match lookup. Used by switches for L2 forwarding. | Hardware ASIC |
| TCAM (Ternary CAM) | L3/ACL | Supports wildcard/ternary matching (0, 1, don’t-care). Used for FIB lookups, ACLs, QoS classification at wire speed. | Hardware ASIC |
CEF (Cisco Express Forwarding)
CEF is the default switching mechanism for all Cisco platforms. It pre-computes forwarding decisions and stores them in the FIB + Adjacency Table, enabling hardware-speed forwarding without CPU involvement per packet.
- Process switching (legacy) โ CPU handles each packet. Slowest. Used as fallback.
- Fast switching (legacy cache) โ First packet CPU-processed and cached; subsequent packets use cache.
- CEF / dCEF โ Distributed CEF. Each line card has its own FIB copy. Fastest.
๐งช Lab Exercises
These labs use Cisco IOS/IOS-XE syntax (Cisco Packet Tracer, GNS3, or CML). Each lab reinforces a key architecture concept.
HSRP Active/Standby Configuration (Topic 1.1.b)
Objective: Configure HSRP between two routers so end devices have a redundant default gateway.
Topology: R1 (Active) and R2 (Standby) connected to same VLAN 10 (192.168.10.0/24). Virtual IP = 192.168.10.1
R1(config)# interface GigabitEthernet0/0 R1(config-if)# ip address 192.168.10.2 255.255.255.0 R1(config-if)# standby version 2 R1(config-if)# standby 10 ip 192.168.10.1 R1(config-if)# standby 10 priority 110 R1(config-if)# standby 10 preempt R1(config-if)# standby 10 authentication md5 key-string Cisco123 R1(config-if)# no shutdown
R2(config)# interface GigabitEthernet0/0 R2(config-if)# ip address 192.168.10.3 255.255.255.0 R2(config-if)# standby version 2 R2(config-if)# standby 10 ip 192.168.10.1 R2(config-if)# standby 10 preempt R2(config-if)# standby 10 authentication md5 key-string Cisco123 R2(config-if)# no shutdown
R1# show standby R1# show standby brief ! Expected output: ! P indicates configured to preempt. ! Interface Grp Pri P State Active Standby Virtual IP ! Gi0/0 10 110 P Active local 192.168.10.3 192.168.10.1
R1(config)# interface GigabitEthernet0/0 R1(config-if)# shutdown ! On R2: R2# show standby brief ! R2 should now show Active state for group 10
Verify CEF Forwarding Tables (Topic 1.6)
Objective: Inspect the RIB, FIB, and Adjacency Table to understand the CEF forwarding chain.
Router# show ip route ! Look for C (connected), S (static), O (OSPF), B (BGP) prefixes ! Best route from each protocol enters the RIB
Router# show ip cef ! Destination Next Hop Interface ! 0.0.0.0/0 10.1.1.1 GigabitEthernet0/0 ! 192.168.1.0/24 attached GigabitEthernet0/1 ! 192.168.2.0/24 10.1.1.1 GigabitEthernet0/0 Router# show ip cef 192.168.2.0 detail ! Shows exact next-hop, outgoing interface, and adj pointer
Router# show adjacency Router# show adjacency GigabitEthernet0/0 detail ! Displays L2 rewrite information: ! Protocol Interface Address ! IP GigabitEthernet0/0 10.1.1.1(7) ! 0 packets, 0 bytes ! epoch 0 ! sourced in sev-epoch 0 ! Encap length 14 ! AABBCC001122DDEEFF003344 (dest MAC + src MAC + ethertype)
Switch# show mac address-table ! Vlan Mac Address Type Ports ! 10 aabb.cc00.1122 DYNAMIC Gi0/1 ! 10 ddee.ff00.3344 DYNAMIC Gi0/2
Router(config)# no ip cef ! Disables CEF (falls back to process switching) Router(config)# ip cef ! Re-enable Router(config)# ip cef accounting ! Enable per-prefix accounting
Three-Tier Campus Design โ Inter-VLAN Routing (Topic 1.1.a)
Objective: Build a three-tier topology with access VLANs, distribution SVIs, and core routing.
! On Access Switch SW-A1: SW-A1(config)# vlan 10 SW-A1(config-vlan)# name USERS SW-A1(config)# vlan 20 SW-A1(config-vlan)# name VOICE SW-A1(config)# interface range Gi0/1 - 24 SW-A1(config-if-range)# switchport mode access SW-A1(config-if-range)# switchport access vlan 10 SW-A1(config)# interface Gi0/0 SW-A1(config-if)# switchport mode trunk SW-A1(config-if)# switchport trunk allowed vlan 10,20
! On Distribution Switch DIST-1: DIST-1(config)# ip routing DIST-1(config)# vlan 10 DIST-1(config)# vlan 20 DIST-1(config)# interface vlan 10 DIST-1(config-if)# ip address 10.10.10.1 255.255.255.0 DIST-1(config-if)# no shutdown DIST-1(config)# interface vlan 20 DIST-1(config-if)# ip address 10.20.20.1 255.255.255.0 DIST-1(config-if)# no shutdown ! Uplink to core (routed port) DIST-1(config)# interface Gi1/0 DIST-1(config-if)# no switchport DIST-1(config-if)# ip address 172.16.1.2 255.255.255.252 DIST-1(config-if)# no shutdown ! OSPF toward core DIST-1(config)# router ospf 1 DIST-1(config-router)# network 10.0.0.0 0.255.255.255 area 0 DIST-1(config-router)# network 172.16.1.0 0.0.0.3 area 0
DIST-1# show ip route DIST-1# ping 10.20.20.100 source 10.10.10.1 DIST-1# show ip ospf neighbor
SD-WAN vEdge โ OMP Route Verification (Topic 1.4)
Objective: Verify OMP sessions and route exchange on a Cisco IOS-XE SD-WAN (cEdge) router.
cEdge# show sdwan omp summary cEdge# show sdwan omp peers ! Displays connected vSmart controllers ! State should be "up" and "established"
cEdge# show sdwan omp routes ! Shows all routes received from vSmart ! Includes tloc-paths (transport locators) for each prefix cEdge# show sdwan omp tlocs ! Shows Transport LOCations (color + system IP + encap)
cEdge# show sdwan ipsec inbound-connections cEdge# show sdwan ipsec outbound-connections cEdge# show sdwan bfd sessions ! BFD monitors each IPsec tunnel health ! State: up | down | AdminDown
cEdge# show sdwan policy from-vsmart ! Displays centralized policies pushed from vManage/vSmart ! Including app-route policies, cflowd, ACLs
SD-Access LISP/VXLAN Fabric Verification (Topic 1.5)
Objective: Verify LISP endpoint registration and VXLAN tunnel operation in an SD-Access fabric.
EdgeNode# show lisp instance-id 4098 ipv4 database ! Shows locally registered EIDs (endpoints connected to this edge) ! EID prefix Locator Pri/Wgt Source State ! 10.1.1.10/32 192.168.100.1 1/50 cfg-intf Reachable
EdgeNode# show lisp instance-id 4098 ipv4 map-cache ! EID prefix Locator TTL Action ! 10.1.2.20/32 192.168.100.2 1d0h forward-native ! This shows the RLOC (VTEP) for a remote endpoint
EdgeNode# show nve peers ! Interface VNI Peer-IP State uptime ! nve1 8192 192.168.100.2 UP 00:45:23 EdgeNode# show nve vni ! VNI Mode BD IngressReplication ! 8192 L2 102 N/A
! From a client on VLAN 10 (10.1.1.10) to remote client (10.1.2.20): ! 1. Client sends to default GW (EdgeNode SVI) ! 2. EdgeNode queries LISP map-server: "Where is 10.1.2.20?" ! 3. Map-server replies: RLOC = 192.168.100.2 ! 4. EdgeNode encapsulates in VXLAN, sends to 192.168.100.2 ! 5. Remote EdgeNode decapsulates, delivers to 10.1.2.20 EdgeNode# debug lisp control-plane itr map-request
Check Your Understanding
Twenty questions on this section. Each answer is explained as you go.
