
Cisco Certified Network Professional
- 24 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Design and troubleshoot CCNP-level enterprise networks: campus switching, OSPF/EIGRP/BGP routing, FHRP, assurance, and IOS-XE troubleshooting.
About
Guides CCNP-level enterprise campus and WAN networking covering VLAN/STP, OSPF/EIGRP/BGP, FHRP, network assurance, and structured troubleshooting on Cisco IOS-XE and Catalyst. A developer or network engineer uses it for enterprise routing/switching design and CCNP prep.
- Campus switching: VLANs, STP/RSTP/MST, EtherChannel, stacking
- Enterprise routing OSPF/EIGRP/BGP and structured troubleshooting
Cisco Certified Network Professional by the numbers
- 24 all-time installs (skills.sh)
- Ranked #804 of 1,039 Cloud & Infrastructure skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cisco-certified-network-professionalAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 24 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Design and troubleshoot CCNP-level enterprise networks: campus switching, OSPF/EIGRP/BGP routing, FHRP, assurance, and IOS-XE troubleshooting.
Files
Cisco Certified Network Professional
When to Use
- Design or troubleshoot enterprise campus LAN switching (VLANs, STP/RSTP/MST, EtherChannel, stacking)
- Plan enterprise routing (OSPF, EIGRP, BGP fundamentals, redistribution, summarization)
- Architect WAN edge services (FHRP, DMVPN/SD-WAN handoff points, QoS at branch/DC edge)
- Integrate wireless at L2/L3 boundaries (controller/AP attachment, guest segmentation touchpoints)
- Implement network assurance (SNMP, NetFlow/IPFIX, syslog, basic telemetry, baseline dashboards)
- Apply security integration (802.1X, ACLs, control-plane protection, device hardening) at the network layer
- Follow structured troubleshooting methodology on Cisco IOS-XE, Catalyst, and Meraki-managed campuses
When NOT to Use
- Carrier- or internet-scale backbone BGP policy, peering, IX, and DCI as primary deliverable →
network-backbone-architect - SD-WAN controller policy, template lifecycle, and overlay operations as primary task →
sd-wan-engineer - Cloud VPC/VNet, landing zone, and cloud-native networking IaC only →
cloud-engineer - Wi-Fi RF surveys, channel planning, and mobility protocol depth →
wireless-wifi-mobility-specialist - Enterprise security program, SOC 2 evidence, or audit control mapping →
information-security-engineer - Physical cabling, rack/power, and DC build without routed campus design →
infrastructure-engineer - IoT/OT edge protocols, BACnet/Modbus gateways, and plant segmentation →
iot-network-edge-engineer
Related skills
| Need | Skill |
|---|---|
| Backbone BGP, WAN/MPLS, DCI, peering, spine-leaf at scale | network-backbone-architect |
| SD-WAN overlay operations, templates, and carrier handoff | sd-wan-engineer |
| Cloud networking implementation and hybrid connectivity | cloud-engineer |
| RF design, WLAN controllers, and mobility architecture | wireless-wifi-mobility-specialist |
| IaC, platform delivery, and DC physical build | infrastructure-engineer |
| IoT/OT edge connectivity and industrial protocols | iot-network-edge-engineer |
| Security program, IAM evidence, and audit readiness | information-security-engineer |
Core Workflows
1. Scope and enterprise architecture
Clarify sites, user/device counts, critical apps, RTO for path loss, and Cisco platform mix (IOS-XE, Catalyst, Meraki).
See `references/ccnp_scope_and_enterprise_architecture.md`.
2. Campus switching and Layer 2
Design VLANs, STP domain, EtherChannel, stacking/VSS, and L2 security boundaries.
See `references/campus_switching_and_layer2.md`.
3. Routing (OSPF, EIGRP, BGP)
Select IGP, plan areas/AS, summarization, redistribution, and enterprise BGP at the edge.
See `references/routing_ospf_eigrp_bgp.md`.
4. WAN edge, QoS, and services
Place FHRP, WAN attachment, marking/queuing, and service modules (NAT, DHCP relay, multicast touchpoints).
See `references/wan_edge_qos_and_services.md`.
5. Assurance and troubleshooting
Baselines, flow telemetry, structured TSHOOT, and change/rollback discipline.
See `references/assurance_troubleshooting_and_operations.md`.
6. Security integration and automation basics
802.1X, ACL placement, control-plane hardening, and Git/NETCONF adjacency without replacing security engineering.
See `references/security_integration_and_automation_basics.md`.
Outputs
- Campus context — sites, tiers, critical flows, and failure domains
- L2/L3 design — VLAN map, STP root plan, routing protocol choice, and summarization boundaries
- Edge services matrix — FHRP, QoS classes, WAN/SD-WAN attachment, and ACL inspection points
- Assurance plan — SNMP/flow targets, baseline KPIs, and escalation playbooks
- Troubleshooting runbook — layered checks (physical → L2 → L3 → app path) with evidence to capture
- Handoff notes — what to defer to backbone, SD-WAN, cloud, wireless, or security peers
Principles
- Hierarchy and summarization — aggregate at distribution/core; keep access simple
- Stability before features — STP root, FHRP priority, and IGP metrics are operational contracts
- Document redistribution — tag, filter, and loop prevention are design requirements, not afterthoughts
- QoS end-to-end — classify at access; trust boundaries explicit at WAN edge
- Measure, then tune — baselines before micro-optimizing timers or metrics
- Design guidance, not exam dumps — teach trade-offs; do not facilitate certification cheating
Assurance, troubleshooting, and operations
Table of contents
1. Network assurance stack 2. Baselines and KPIs 3. SNMP and polling 4. Flow telemetry (NetFlow, IPFIX) 5. Syslog and telemetry basics 6. Structured troubleshooting methodology 7. Change management and rollback 8. Evidence capture template
Network assurance stack
| Layer | Tooling (examples) | Purpose |
|---|---|---|
| Synthetic | IP SLA, TWAMP | Path availability and latency |
| Polling | SNMP, gNMI | Device health, interface counters |
| Flows | NetFlow, IPFIX | Who talks to whom, capacity |
| Logs | Syslog, AAA | Config changes, auth failures |
| Dashboards | NMS, Meraki, DNA Center | Operator single pane |
CCNP depth: specify what to collect and thresholds, not vendor SKU selection alone.
Baselines and KPIs
Establish 7-day normal before alerting:
| KPI | Typical source | Alert when |
|---|---|---|
| Interface utilization | SNMP ifIn/Out | >70% sustained 15m (tune per link) |
| CPU/memory | SNMP ENTITY | >80% sustained |
| STP topology change | Syslog | TCN storm |
| BGP prefixes | SNMP/CLI | Drop below learned baseline |
| Latency to gateway | IP SLA | Above SLA threshold |
| Error counters | SNMP | CRC/input errors increasing |
Document business hours vs backup window profiles separately.
SNMP and polling
Versions: prefer SNMPv3 (authPriv) on production; retire v2c community strings on internet-facing management.
Polling discipline:
- Poll interval matched to KPI (60s interface, 300s inventory)
- Limit OID walks on large switches during peak
- Use interface indexes consistently; re-index after reload
Useful categories:
ifTable— status, errors, utilizationcpmCPU/ memory OIDs — control plane health- Entity MIB — temperature, power supplies
- BGP/OSPF MIBs — neighbor state (validate against CLI during incidents)
Flow telemetry (NetFlow, IPFIX)
Exporter placement: distribution or WAN edge — balance visibility vs export volume.
Design checklist:
- [ ] Sampler rate on high-speed links
- [ ] Exporter destination capacity (collector sizing)
- [ ] Template refresh for flexible NetFlow v9/IPFIX
- [ ] Retention aligned with security investigations (coordinate with security peer)
Use cases:
- Top talkers during congestion
- Verify QoS class distribution
- Post-incident five-tuple reconstruction (not a substitute for full PCAP on all links)
Syslog and telemetry basics
Syslog:
- Centralize with NTP-synced timestamps
- Severity filtering: ERR/CRIT to paging; INFO for config audit
- Separate management VRF transport where possible
Streaming telemetry (awareness):
- gRPC/gNMI for high-cardinality counters
- Model-driven telemetry complements SNMP for spine-leaf at scale
- Document subscription paths in automation runbooks
Meraki: dashboard events and flow logs — map to enterprise SIEM fields for hybrid campuses.
Structured troubleshooting methodology
Use a consistent layer model (adapt to symptom):
1. Scope — Who/what/VLAN/site? When started? Recent change?
2. Physical — Link up? Errors? PoE? Optics?
3. L2 — VLAN, trunk, MAC, STP blocking?
4. L3 — ARP, FHRP, routing table, ACL?
5. Path — Traceroute, CEF, PMTU, asymmetric routing?
6. App — DNS, firewall, proxy (hand off if app-owned)Divide-and-conquer:
- Test from known-good port or device
- Compare working vs broken VLAN or site
- Isolate change — rollback if within maintenance window
Avoid:
- Random timer tuning without evidence
- Clearing routing tables during peak without capture
- Sharing configs with PII or live credentials in tickets
Change management and rollback
| Step | Action |
|---|---|
| Plan | Rollback config snippet stored in ticket |
| Pre-check | Baseline show commands archived |
| Window | Notify NOC; freeze parallel changes |
| Execute | One logical change per window when possible |
| Verify | KPI + functional test from user VLAN |
| Post | Update diagram and IPAM if addressing changed |
Golden config: Git-backed templates for IOS-XE; Meraki network bind notes for dashboard.
Evidence capture template
Paste into incident tickets:
Device:
Symptom:
Scope (users/VLAN/sites):
Time started (TZ):
Recent changes:
---
show ip interface brief
show vlan brief
show spanning-tree vlan <id>
show standby brief
show ip route <dst>
show ip ospf neighbor
show ip bgp summary
show interfaces <if> counters errors
traceroute <dst> source <src>
---
Resolution:
Root cause category: L1 / L2 / L3 / WAN / Security / ExternalFor chronic issues, open problem record with trend graphs from NMS.
Campus switching and Layer 2
Table of contents
1. VLAN design 2. Spanning Tree (STP/RSTP/MST) 3. EtherChannel and physical design 4. Stacking and redundancy models 5. L2 security and hygiene 6. Wireless integration touchpoints 7. Common failure patterns 8. Verification commands (IOS-XE)
VLAN design
Principles:
- One subnet per VLAN at access; avoid stretching subnets across sites without documented L2 extension risk
- Separate voice, guest, management, and user VLANs by policy
- Keep VLAN count manageable; use VRF-lite at L3 edge when security zones need routing separation without VLAN sprawl
| VLAN type | Typical placement | Notes |
|---|---|---|
| User data | Access switch | 802.1X or MAB |
| Voice | Access + QoS trust | DSCP/CoS plan with wan_edge_qos_and_services.md |
| Guest | DMZ or isolated VRF | No route to corporate without firewall |
| Management | OOB or dedicated VRF | Restrict source ACLs |
| AP management | Local to WLC or Meraki | Document DHCP option 43 / discovery |
Inter-VLAN routing: prefer distribution or core as L3 gateway (router-on-a-stick only for small sites).
Spanning Tree (STP/RSTP/MST)
Default preference: RSTP (rapid PVST+ or MST) with explicit root bridge placement.
Root bridge plan:
| Region | Root primary | Root secondary |
|---|---|---|
| Access block A | Distribution switch A | Distribution switch B |
| Building floor | Access stack master (if documented) | Alternate path via uplink |
MST when multiple VLAN groups need different forwarding:
- Instance 0: bulk data VLANs
- Instance 1: voice or critical VLANs (optional)
- Document name, revision, and VLAN-to-instance mapping in the runbook
Port roles:
- Edge ports:
spanning-tree portfast+ BPDU guard on access/host ports - Uplinks: normal RSTP; no portfast toward switches
- Disable STP only with extreme justification (and loop risk acceptance)
Alignment with FHRP: STP root should live on the same distribution switch that owns active FHRP for that VLAN (see wan_edge_qos_and_services.md).
EtherChannel and physical design
LACP (preferred) between access ↔ distribution and distribution ↔ core:
- Match speed, duplex, and MTU on member links
- Use port-channel consistent hashing; document critical flows if ECMP polarization matters
- Mismatched configs are a top cause of intermittent loss
Design rules:
- Dual homing access switches to two distribution switches when budget allows
- Avoid vPC/MEC complexity unless operations can support it; defer data-center MLAG depth to backbone peers
Stacking and redundancy models
| Model | Use case | CCNP-level notes |
|---|---|---|
| Stackwise / stacking | Access or small distribution | Single control plane; plan stack master/replacement |
| VSS / virtual switching | Distribution pair | Reduces STP complexity; document split-brain recovery |
| Traditional dual uplink | Most campuses | STP + FHRP; well-understood ops |
Stacking checklist:
- Power diversity across members
- Stack bandwidth vs east-west load
- Hot spare or RMA process for member failure
L2 security and hygiene
| Control | Purpose |
|---|---|
| BPDU Guard | Block rogue switches on access |
| Root Guard | Protect root placement on uplinks |
| Loop Guard / UDLD | Detect unidirectional links (where supported) |
| DHCP Snooping | Mitigate rogue DHCP on access VLANs |
| Dynamic ARP Inspection | Pair with DHCP snooping for user VLANs |
| Storm control | Limit broadcast/multicast storms |
Private VLANs — use sparingly; document promiscuous/isolated/community mapping.
Wireless integration touchpoints
This skill does not replace wireless-wifi-mobility-specialist for RF design.
L2/L3 boundaries to document:
- AP VLAN vs client VLANs
- FlexConnect/local mode vs central switching (controller-dependent)
- mDNS/Bonjour gateway requirements
- Multicast for video (IGMP snooping, querier placement)
Meraki: VLANs and SSIDs mapped in dashboard; confirm same subnet plan as IOS-XE campuses.
Common failure patterns
| Symptom | Often caused by |
|---|---|
| Intermittent connectivity | STP reconvergence, unidirectional link, port-channel mismatch |
| One VLAN works, others do not | VLAN trunk pruning, wrong SVI, FHRP mismatch |
| Slow roaming or one-way audio | QoS trust, wrong CoS/DSCP, oversized STP domain |
| Duplicate IP | Rogue DHCP, HSRP misconfiguration |
Verification commands (IOS-XE)
Use as structured evidence during TSHOOT (not exhaustive):
show spanning-tree summary
show spanning-tree vlan <id>
show etherchannel summary
show interfaces trunk
show vlan brief
show mac address-table dynamic vlan <id>
show cdp neighbors detailCapture before/after for change windows: STP root ID, port-channel state, trunk allowed VLANs.
CCNP scope and enterprise architecture
Table of contents
1. Role and boundaries 2. CCNP Enterprise alignment 3. Campus hierarchy model 4. Discovery checklist 5. Addressing and naming 6. Platform context (IOS-XE, Catalyst, Meraki) 7. Deliverable checklist 8. Peer handoffs
Role and boundaries
This skill covers CCNP-level enterprise networking: multi-site campuses, branch WAN attachment, and integrated security/assurance at the network engineering layer. Depth is design and operational workflow, not CCIE lab scripting or certification item memorization.
In scope:
- Three-tier and collapsed-core campus designs
- L2/L3 integration for wired and wireless attachment
- Enterprise IGP (OSPF, EIGRP) and BGP fundamentals at WAN/DC edge
- FHRP, redistribution, IPv4/IPv6 dual-stack planning
- Enterprise QoS, ACLs, 802.1X at access/distribution
- SNMP, NetFlow/IPFIX, syslog, and basic telemetry for assurance
- Structured troubleshooting on Cisco platforms
Out of scope (use peer skills):
| Topic | Skill |
|---|---|
| Internet/peering/DCI BGP policy at carrier scale | network-backbone-architect |
| SD-WAN template/overlay day-two ops | sd-wan-engineer |
| AWS/Azure/GCP VPC and cloud IaC | cloud-engineer |
| RF planning, RRM, and WLAN mobility depth | wireless-wifi-mobility-specialist |
| SOC 2 / ISO audit programs | information-security-engineer |
| Rack/cable plant without routing design | infrastructure-engineer |
| IoT/OT protocols and plant gateways | iot-network-edge-engineer |
CCNP Enterprise alignment
Map work to common CCNP Enterprise themes without treating the skill as an exam guide:
| Domain (conceptual) | This skill emphasizes |
|---|---|
| Architecture | Hierarchy, modularity, failure domains, dual-stack |
| Virtualization | VLANs, VRF-lite at enterprise edge, overlay handoff to SD-WAN |
| Infrastructure | Switching, routing, FHRP, WAN attachment |
| Network assurance | Baselines, flows, SNMP, structured TSHOOT |
| Security | 802.1X, ACLs, CPP, device hardening at network layer |
| Automation | NETCONF/RESTCONF awareness; Git-backed config discipline |
Do not reproduce exam item banks, brain-dump answers, or unauthorized certification content.
Campus hierarchy model
Typical enterprise campus roles:
[ Access ] ──► [ Distribution ] ──► [ Core ] ──► [ WAN / DC edge ]
│ │ │
User VLANs L3 + FHRP High-speed
802.1X Summarization routing
PoE ACL inspection BGP (if edge)Collapsed core (distribution + core combined) is valid for smaller sites when:
- East-west traffic stays local or hairpins acceptably
- STP domain and FHRP ownership remain documented
- Growth path to three-tier is captured in the design record
Label failure domains: one access switch failure vs distribution pair vs WAN path.
Discovery checklist
Gather before locking VLAN or routing design:
| Input | Why it matters |
|---|---|
| Site count and criticality tier | Hub vs spoke, FHRP placement |
| User/device counts per VLAN | Subnet sizing, DHCP scope |
| Application latency/jitter needs | QoS classes, local vs central services |
| Wireless controller model | L2 adjacency, guest segmentation |
| Existing IGP and pain points | Migration vs greenfield |
| WAN type (MPLS, DIA, SD-WAN) | Handoff to sd-wan-engineer or backbone peer |
| Security zones (PCI, guest, IoT) | VRF/VLAN map; defer OT depth to IoT peer |
| Operations tooling | SNMP, NetFlow, syslog, ticketing integration |
| Change windows and rollback | Maintenance discipline |
Minimum artifacts:
- Traffic matrix (site × site × app × peak Mbps) — simplified is acceptable
- RTO for single-link and single-node failure at distribution
- Address plan with summarization boundaries documented
Addressing and naming
IPv4:
- Use RFC1918 with deliberate summarization at distribution/core
- Reserve point-to-point
/30or/31(where supported) for routed links - Document DHCP relay placement (distribution vs centralized)
IPv6:
- Plan dual-stack or IPv6-only islands with documented DNS/NTP reachability
- Unique Local (ULA) vs global — align with WAN and cloud peers early
Naming:
- Consistent hostname scheme (
site-role-id) - Interface descriptions: remote device, circuit ID, VLAN purpose
- Document VRF names if used (guest, voice, management)
Platform context (IOS-XE, Catalyst, Meraki)
| Platform | Typical use in this skill |
|---|---|
| Catalyst (access/distribution) | STP, EtherChannel, stacking, 802.1X |
| IOS-XE (routers, L3 switches) | OSPF/EIGRP/BGP, FHRP, QoS, WAN interfaces |
| Meraki (cloud-managed) | Simplified campus/branch; document API/dashboard limits vs CLI designs |
When Meraki and traditional IOS-XE coexist:
- Document automation boundary (dashboard templates vs CLI/Git)
- Align VLAN and subnet plans across both worlds
- Escalate advanced routing policy to backbone or SD-WAN peers
Deliverable checklist
- [ ] Site inventory with tier and platform list
- [ ] Logical topology (L2/L3 boundaries, FHRP, summarization points)
- [ ] VLAN/VRF matrix with security zone labels
- [ ] Routing protocol selection with area/AS rationale
- [ ] WAN/SD-WAN attachment diagram with peer ownership
- [ ] QoS policy summary (classes, markings, queue roles)
- [ ] Assurance targets (SNMP OIDs/polls, flow exporters, syslog)
- [ ] TSHOOT playbook outline for top three failure scenarios
Peer handoffs
| Trigger | Hand off to |
|---|---|
| Full-mesh BGP, IX/peering, anycast, DCI L3 | network-backbone-architect |
| vManage templates, ZTP, overlay path selection | sd-wan-engineer |
| VPC, TGW, Direct Connect, cloud VPN | cloud-engineer |
| Survey, channel width, 802.11k/v/r design | wireless-wifi-mobility-specialist |
| Audit control mapping and evidence | information-security-engineer |
| Smart building sensors, BACnet, edge gateways | iot-network-edge-engineer |
Routing — OSPF, EIGRP, BGP
Table of contents
1. Protocol selection 2. OSPF enterprise design 3. EIGRP enterprise design 4. BGP fundamentals at the enterprise edge 5. Redistribution and loop prevention 6. Summarization and filtering 7. IPv6 routing notes 8. Verification and troubleshooting
Protocol selection
| Factor | OSPF | EIGRP | Notes |
|---|---|---|---|
| Multi-vendor campus | Strong default | Cisco-centric | OSPF common in mixed estates |
| Large Cisco-only WAN | Either | Familiar metrics | Document metric manipulation policy |
| Staff skills | Area design literacy | DUAL concepts | Training plan matters |
| IPv6 | Native OSPFv3 | EIGRP for IPv6 (legacy) | Prefer OSPFv3 for dual-stack greenfield |
Default guidance: OSPF for new enterprise multi-site designs unless EIGRP is mandated by existing core.
Defer internet-scale BGP policy to network-backbone-architect.
OSPF enterprise design
Area types:
- Area 0 at core/distribution hub
- Normal areas for campuses; stub/NSSA at remote sites to limit LSDB size
Design checklist:
- [ ] One logical ABR layer (distribution) summarizing into area 0
- [ ] Passive interfaces on user-facing SVIs; adjacencies only on routed links
- [ ] BFD on WAN/core adjacencies where fast failure detection is required
- [ ] Reference bandwidth adjusted on high-speed links (
auto-cost reference-bandwidth) - [ ] Authentication (MD5 or SHA) on all adjacencies in security-sensitive environments
LSA flooding discipline:
- Avoid excessive type-7/external in NSSA without summarization
- Filter default originate only from documented edge devices
Timers: tune only with baseline captures; document hello/dead on WAN links.
EIGRP enterprise design
When EIGRP remains:
- Document AS number, named mode vs classic, and stub sites
- Use EIGRP stub on remote spokes to limit query scope
- Leak maps and offset lists require change control — easy to create loops
Metrics:
- Understand K-values; avoid arbitrary bandwidth/delay tweaks without traffic matrix
- Variance for unequal cost — rare in campus; document if used
BGP fundamentals at the enterprise edge
Enterprise BGP scope here: single- or dual-homed internet, MPLS CE, or hub route reflector at DC — not full internet table engineering.
Typical roles:
| Role | Function |
|---|---|
| CE router | Peers with ISP or MPLS PE; receives default or partial routes |
| DC edge | Originates enterprise aggregates; filters RFC1918 leaks |
| RR (optional) | Hub spokes in large hub-and-spoke VPN designs |
Checklist:
- [ ] ASN private vs public documented
- [ ] Prefix filtering inbound (bogons) and outbound (only owned prefixes)
- [ ] Maximum-prefix limits on CE sessions
- [ ] Local preference / MED policy documented if multi-homed
- [ ] BGP TTL security and GTSM where provider supports
SD-WAN handoff: underlay BGP may coexist with overlay; coordinate with sd-wan-engineer for path preference.
Redistribution and loop prevention
Redistribution is a design event, not a config shortcut.
Rules:
1. Redistribute in one direction per routing domain boundary when possible 2. Use route tags to identify source protocol 3. Apply distribute-lists or route-maps on both protocols at the boundary 4. Never redistribute BGP into IGP without filtering defaults at multiple points 5. Prefer static discard aggregates over leaking fine-grained externals
OSPF ↔ EIGRP (migration):
- Use seed metrics consistently (type E1/E2, EIGRP delay/bandwidth)
- Staged migration: mutual redistribution only in maintenance window with loop monitoring
External routes: originate summaries at ABR/edge, not from access layer.
Summarization and filtering
| Location | Summarize | Rationale |
|---|---|---|
| Distribution → Core | Per-building or per-site subnets | Stable LSDB |
| WAN edge | Enterprise supernets to provider | Minimize updates |
| Branch stub | Default route only | Simplicity |
Filtering:
- Prefix lists for exact match on redistributed nets
- Community tags for policy at WAN (coordinate with backbone peer if used)
IPv6 routing notes
- OSPFv3 separate process or address-family under single OSPF (platform-dependent)
- Plan link-local adjacencies on point-to-point; document global addressing on SVIs
- ICMPv6 RA vs DHCPv6 — align with access design
- Filter fe80::/10 leaks at edge same as IPv4 bogon discipline
Verification and troubleshooting
Layered checks:
1. Interface up/up, correct subnet, MTU match 2. Neighbor state (Full for OSPF; up for EIGRP; Established for BGP) 3. Routing table for prefix — which protocol, which AD 4. Forwarding path — traceroute, CEF/FIB entry
Useful show commands:
show ip ospf neighbor
show ip ospf database
show ip eigrp neighbors
show ip route <prefix>
show ip bgp summary
show ip bgp <prefix>
show ip protocolsFor redistribution bugs, compare routing table vs protocol RIB and capture route-map hit counts during change window.
Security integration and automation basics
Table of contents
1. Scope at the network layer 2. 802.1X and port-based access 3. ACL design and placement 4. Control plane protection 5. Device hardening checklist 6. Management plane security 7. Automation and programmability basics 8. Handoffs to security peers
Scope at the network layer
This reference covers integration of security controls on campus and WAN devices — not enterprise GRC, pentest programs, or cloud CSPM.
In scope:
- 802.1X / MAB on access ports
- Infrastructure ACLs and zone-based filtering at distribution
- Control Plane Policing (CPP) and management ACLs
- Cisco IOS-XE hardening baselines (conceptual)
- Awareness of NETCONF/RESTCONF and Git-backed config
Out of scope:
| Topic | Skill |
|---|---|
| SOC 2 / ISO evidence pipelines | information-security-engineer |
| Full zero-trust product architecture | Security architecture peers |
| Firewall rule lifecycle (Palo Alto, FTD) | Security engineering / vendor runbooks |
802.1X and port-based access
Components:
| Component | Role |
|---|---|
| Supplicant | Client (802.1X on NIC) |
| Authenticator | Access switch port |
| Authentication server | RADIUS (ISE, NPS, etc.) |
Deployment modes:
- Single-host access mode on user ports
- MAB for printers/IoT without supplicant — limited VLAN only
- Guest via separate SSID or VLAN after portal (wireless peer for portal depth)
Design checklist:
- [ ] RADIUS redundancy (primary/secondary)
- [ ] Dynamic VLAN assignment documented per authorization profile
- [ ] Guest cannot reach RFC1918 corporate without firewall
- [ ] Critical auth vs open auth policy for RADIUS outage (document risk)
- [ ] Reauth timers for wireless roaming coordination
Meraki: 802.1X and RADIUS in dashboard; align authorization VLANs with IOS-XE campuses.
ACL design and placement
Principles:
- Deny by exception at trust boundaries; permit established/related on stateful firewalls
- Infrastructure ACLs on SVIs facing servers or management zones
- Avoid mega-ACLs on core — aggregate rules; log sparingly
| Placement | Typical purpose |
|---|---|
| Access port | Not common; prefer 802.1X |
| Distribution SVI | Inter-VLAN segmentation |
| WAN edge | Bogon filter, anti-spoofing |
| Management | SSH/HTTPS source restriction |
IPv6: separate ACLs; remember ICMPv6 essentials for ND (do not over-filter on internal segments).
Object groups and named ACLs improve readability; comment with ticket IDs.
Control plane protection
Protect CPU-bound processes from flooding:
- Control Plane Policing (CPP) — classify ARP, BGP, SNMP, SSH
- CoPP policy maps — police or drop excess classes
- rate-limit routing protocol neighbors on untrusted interfaces
- Disable unused services (finger, pad, etc. on legacy images)
BGP/OSPF authentication on all external and WAN adjacencies per policy.
Device hardening checklist
Apply per platform baseline (CIS or vendor guide):
- [ ] SSH v2 only; disable Telnet
- [ ] Strong passwords or certificate-based admin auth
- [ ] Enable secret type 8/9 where supported
- [ ] Login banner (legal notice)
- [ ] AAA (TACACS+/RADIUS) for admin with local fallback documented
- [ ] Privilege levels — least privilege for operators
- [ ] SNMPv3 only; no default communities
- [ ] NTP authentication where required
- [ ] Unused ports shutdown in default template
- [ ] BOOTP/IP source routing disabled per hardening guide
- [ ] Image integrity — signed images, secure boot where available
Meraki: dashboard RBAC, MFA on admin accounts, API key rotation.
Management plane security
| Control | Implementation |
|---|---|
| Out-of-band management | Dedicated Mgmt VRF or OOB network |
| Jump hosts | SSH only via bastion; no direct internet SSH to devices |
| Segmentation | ACL: NMS subnets only to SNMP/SSH |
| Config backup | Encrypted Git; no secrets in repo |
| Certificate lifecycle | HTTPS for NETCONF/gRPC |
ZTP/PNP: validate chain of trust for bootstrap; staging VLAN isolated.
Automation and programmability basics
Goals at CCNP depth: consistency and auditability, not full NetDevOps program.
| Mechanism | Use |
|---|---|
| Git | Versioned configs, PR review for network changes |
| NETCONF/RESTCONF | Structured config push on IOS-XE |
| Ansible | Idempotent playbooks for repeatable baselines |
| Meraki API | Dashboard automation for branch templates |
| DNA Center (if deployed) | Intent templates; document drift handling |
Guardrails:
- Dry-run and rollback snippet per change
- Secrets in vault, not variables in plain Git
- Test in lab or maintenance window for routing policy changes
Defer Terraform cloud networking primary design to cloud-engineer.
Handoffs to security peers
| Scenario | Escalate to |
|---|---|
| Enterprise security architecture, SASE, ZTNA | Security architecture / information-security-engineer |
| Pentest findings on network devices | Remediation with security engineering |
| SIEM correlation rules for NetFlow/syslog | SOC / detection engineering |
| Identity policy (AD groups, cert templates) | Identity team with 802.1X data from network |
Network engineering delivers reachability, segmentation hooks, and telemetry — security peers own control frameworks and attestation.
WAN edge, QoS, and services
Table of contents
1. WAN attachment models 2. FHRP (HSRP, VRRP, GLBP) 3. SD-WAN adjacency (design level) 4. Enterprise QoS framework 5. NAT, DHCP, and common services 6. Multicast touchpoints 7. IPv4/IPv6 at the edge 8. Operational checklist
WAN attachment models
| Model | CCNP-level design notes |
|---|---|
| Single DIA | Default route; stateful firewall often north of CE |
| Dual DIA | BGP or static tracking; asymmetric routing awareness |
| MPLS L3VPN | CE peers with PE; hub site may summarize |
| DMVPN / IPsec | Hub-spoke crypto overlay; NHRP and routing stability |
| SD-WAN | Underlay + overlay; defer template ops to sd-wan-engineer |
Document for each site:
- Circuit IDs, bandwidth, MTU, and provider NOC
- Primary/backup selection mechanism (routing metric, IP SLA, SD-WAN policy)
- Demarcation — who owns CPE, firewall, and public IP space
FHRP (HSRP, VRRP, GLBP)
Goal: consistent default gateway for VLANs with sub-second failover when distribution pair fails.
| Protocol | Notes |
|---|---|
| HSRP | Cisco default; groups per VLAN/SVI |
| VRRP | Standards-based; interoperable |
| GLBP | Load-sharing AVG; plan ARP and forwarding tables |
Design rules:
- Align active FHRP with STP root for each VLAN
- Use preempt with sensible delay to avoid flapping
- Track WAN interface or IP SLA to withdraw priority on uplink loss
- Document virtual MAC impact on downstream switches (port-security)
Authentication: enable FHRP auth on shared segments in untrusted L2 domains.
SD-WAN adjacency (design level)
At CCNP depth, specify handoff points only:
- Underlay reachability (BGP/OSPF/static) between CE and provider
- Tunnel endpoints and local breakout policy ownership (
sd-wan-engineer) - Application SLA classes mapped to DSCP before overlay encapsulation
- Dual CPE vs single CPE with diverse last-mile
Avoid duplicating vManage policy lifecycle here.
Enterprise QoS framework
End-to-end model (simplified):
[ Classify at access ] → [ Trust boundary ] → [ Queue at WAN edge ] → [ Provider COS ]Common classes:
| Class | Applications | Marking (example) |
|---|---|---|
| Voice | RTP telephony | EF / DSCP 46 |
| Video | Real-time video | AF41 or CS4 per policy |
| Critical data | ERP, auth | AF31 |
| Best effort | General user | BE |
| Scavenger | Backup | CS1 |
Principles:
- Mark once close to source (switch port trust or explicit ACL)
- Police guest and scavenger at access or distribution
- Shape to WAN CIR at edge — know provider shaping vs policing
- Queue on egress WAN: priority queue for voice; WFQ/CBWFQ for others
Meraki: QoS rules in dashboard; align DSCP with IOS-XE sites for hybrid WAN.
NAT, DHCP, and common services
| Service | Placement | Notes |
|---|---|---|
| DHCP | Centralized server or local relay | Option 43 for APs; document lease time |
| DNS | Internal resolvers | Split-horizon for guest |
| NAT | Edge firewall or router | PAT for IPv4; document statics for servers |
| NTP | Stratum hierarchy | Authentication on management plane |
| SNMP/syslog | See assurance reference | Separate management VRF if used |
NAT64/DNS64 — only with explicit IPv6 program; document app compatibility.
Multicast touchpoints
Not full multicast engineering — document when present:
- IGMP snooping on access VLANs with video
- PIM at distribution/core if enterprise IPTV
- RP placement and MSDP (if used) — escalate complex designs to backbone peer
IPv4/IPv6 at the edge
- Dual-stack: parallel policies for ACLs, QoS, and routing
- Default routes: separate v4/v6 next hops; track object per family
- Provider delegations: document PA vs PI for IPv6
Operational checklist
- [ ] FHRP priority/tracking matches STP and WAN primary path
- [ ] QoS policy applied on correct interface direction (usually egress WAN)
- [ ] Shaper rate ≤ contracted CIR with overhead accounting
- [ ] ACLs permit established; deny RFC1918 ingress on internet-facing interfaces
- [ ] IP SLA probes for critical SaaS or next-hop validation
- [ ] Runbook for WAN failover test quarterly