Logo
  • Deals
    • Hardware - Overview
      • Mobile Computing - Overview
      • Notebooks
      • Mobile Workstations
      • Tablets
      • Smartphones & Mobile Phones
      • Wearables
      • Mobile Computing Warranties & Services
      • Mobile Computing Accessories
      • Mobile Computing Spare Parts
      • Communication & Conferencing - Overview
      • Conference Systems
      • VoIP Telephony
      • Headsets
      • Webcams
      • Communication Warranties & Services
      • Communication Accessories
      • IT Infrastructure - Overview
      • Servers
      • Storage
      • Uninterruptible Power Supply
      • Network
      • Security
      • Racks
      • IT Infrastructure Warranties & Services
      • IT Infrastructure Accessories
      • IT Infrastructure Spare Parts
      • Computing - Overview
      • PCs
      • Workstations
      • Thin Clients
      • All-in-One PCs
      • Point of Sale & Point of Information
      • Computing Warranties & Services
      • Computing Accessories
      • Computing Spare Parts
      • Peripherals - Overview
      • Monitors
      • Public Displays
      • TVs
      • Projectors
      • Input Devices
      • Audio, Photo & Video
      • Peripherals Warranties & Services
      • Peripherals Accessories
      • Printers & Scanners - Overview
      • Printers
      • Label Printers
      • Disc Duplicators
      • Scanners
      • Barcode Scanners
      • Mobile Data Collection
      • Consumables
      • Warranties & Services
      • Printer & Scanner Accessories
      • Printer Spare Parts
      • Components - Overview
      • SSDs & HDDs
      • Memory
      • Graphics Cards
      • Drives & Enclosures
      • Interfaces & Controllers
      • Storage Media
      • Power Supplies
      • Processors
      • Component Accessories
      • Connectivity - Overview
      • Network Connectivity
      • PC Connectivity
      • USB Connectivity
      • Power Connectivity
      • Phone Connectivity
      • Device Servers
      • Extenders & Splitters
      • Connectivity Accessories
      • Office Equipment - Overview
      • Organisation & Ergonomics
      • Smart Home
      • Cleaning Products
      • Safety, Security & Protection
      • Office Appliances
      • Mounting Solutions
      • Office Furniture
      • Batteries
      • Office Equipment Accessories
      • Outlet - Overview
      • B-Stock
    • Software - Overview
      • Storage, Backup & Recovery - Overview
      • Client Backup & Recovery
      • Backup, Recovery & Archiving
      • Server Backup & Recovery
      • Security Software - Overview
      • Endpoint Security
      • E-mail Security
      • Security Suites
      • Mobile Security
      • Network Security
      • Cloud Security
      • Gateway Security
      • Management & Training
      • Development Software - Overview
      • Project Management & Collaboration
      • Collaboration Software - Overview
      • Communication
      • Document Management
      • File Sharing
      • Office Applications - Overview
      • Office Software & Add-ons
      • Creative Design & Publishing
      • Infrastructure Software - Overview
      • Operating Systems
      • Monitoring & Reporting
      • Software Deployment & Maintenance
      • Print Management
      • Optimisation
      • Virtualisation - Overview
      • Desktop Virtualisation
      • Infrastructure & Management
    • IT Solutions - Overview
      • Business Applications - Overview
      • Collaboration
      • Enterprise Resource Planning
      • DMS & ECM
      • Template Management System Docunize
      • Cloud solutions - Overview
      • Multi-Cloud
      • Public cloud
      • Clouds-Shop
      • FinOps (Financial Operations)-Service
      • Data & Analytics - Overview
      • Data platform and integration
      • Analytics & AI
      • Data visualisation
      • Data strategy
      • Data Centre - Overview
      • Multi Cloud
      • Modular Data Center Competence
      • Hyper Converged Infrastructure
      • Software-defined Datacenter
      • SAP HANA Infrastructure
      • IoT/AI - Overview
      • Bechtle Control Suite
      • Servinvent | Platform for collating medical devices
      • Modern Workplace - Overview
      • 360° Workplace of the Future
      • Device as a Service
      • Modern meetings
      • Communication and Collaboration
      • Azure Virtual Desktop Solutions
      • Mobile working ▷ Remote & flexible on the road
      • Managed Workplace Services
      • Efficient room management
      • Workplace Security
      • Networking - Overview
      • Data Centre Networking
      • Enterprise Networking
      • Bechtle service bundles for Cisco infrastructure
      • IT Security - Overview
      • Application Security
      • Cloud Security
      • Cyber Security
      • Data Centre Security
      • Data protection and information security
      • Infrastructure & Perimeter Security
      • IAM Identity & Access Management
      • Security awareness training
      • Ransomware
      • Cyber Defence Centre
      • Display solutions - Overview
      • The Reception
      • Wayfinding
      • Employee Communications
    • IT Services - Overview
    • Service Desk
      • Consulting Services - Overview
      • Cloud Consulting
      • Managed Services - Overview
      • Printing Services
      • Azure Operations
      • 360° Managed IT
      • Bechtle Prime Support
    • Onsite Services
    • Professional Services
      • Software Asset Management - Overview
      • SAM as a Service
      • SAM Baseline
      • SAM Solution Advisory
      • SAM Cloud Readiness
      • SAM Consulting
      • SAM Century Platform
      • SAM Inventory2go
      • Workplace Services - Overview
      • Assessment, design and procurement
      • Staging and Rollout Services
      • IMAC/RD Services
      • Break&Fix service
      • Customised IT Accessories
      • Financial Services - Overview
      • Consultation
      • Structuring
      • Financing
      • E-Procurement - Overview
      • My Bechtle
      • ERP Connection
      • Electronic invoicing
      • Quotes
      • Framework agreements
      • Special conditions
      • Promotion Products - Overview
      • New in
      • USB Sticks
      • Wireless Charging Station
      • Powerbanks
      • ProPro range
      • Lifestyle
      • The Webkey
      • 3D Promotional Products
      • Digital Prints Under Tempered Glass
      • Quick Service
      • Process Flow
    • 360° Managed-IT - Overview
    • 360° Managed IT on Microsoft Azure
    • 360° swiss cube
    • 360° colocation
    • 360° infrastructure
    • 360° firewall
    • 360° network
    • 360° backup control
    • 360° cloud backup
    • 360° monitoring
    • 360° CIRT
    • Career - Overview
      • Bechtle as an employer - Overview
      • Development
      • Benefits
      • Departments - Overview
      • IT
      • Sales
      • Other departments
    • Vocational education
    • Application process
    • Career Contact
    • Jobs
    • About Bechtle - Overview
      • Company - Overview
      • Management
      • Bechtle management in Switzerland
      • Locations
      • Bechtle Group Companies
      • Company Development
      • Vision 2030
      • Certifications
      • Bechtle in Switzerland
      • Investors - Overview
      • Bechtle Share
      • Publications
      • Financial Calendar
      • General Meeting
      • Corporate Governance
      • Investors Contact
      • Retail Investors
      • Software revenue according to IFRS 15
    • Sustainability / CSR
      • Events - Overview
      • Bechtle IT Forum 2025 - Replay
      • Webinar Replay Bechtle
      • Webinar: Intel Xeon 6 (Only German)
      • Bechtle X-MAS Market. (Only French)
      • Webinar: Discover Cybersecurity with Arctic Wolf (Only German)
    • References
      • Public Sector - Overview
      • Schools and IT
      • OCRE with Bechtle
      • International business with Bechtle - Overview
      • Global IT Alliance
    • Partners
      • Contact - Overview
      • Bechtle direct Rotkreuz
      • Bechtle direct Dübendorf
      • Bechtle direct AG Schweiz Morges
      • Bechtle Schweiz AG
      • Support
      • News - Overview
      • Newsroom
      • Corporate News
      • Newsletter
      • Bechtle Blog CH
      • Podcast. bits & bytes
About Bechtle
News
Bechtle Blog CH
Network
An intelligent network - tips from our expert Miroslav Kosut
cisco-enterprise-network_1440x400
Network - Jan 27, 2023

An intelligent network for more transparency and security in the company

by Miroslav Kosut

Large networks with their end devices are difficult to manage? Our Cisco expert Miroslav Kosut knows: that can be changed! Instead of many manual interventions, a single controller in the network can do the work for you. The network thus becomes an intelligently and centrally managed overall system.

The whole is more than the sum of its parts! This also and especially applies to networks. Until now, you connected a device with its IP address to a network and had to laboriously integrate each new component manually. That required manpower and time, a lot of time! Or the new device simply got all the rights that were there - regardless of whether the device or its user had them at all. Until now, networks have been really complex - both in terms of construction and management. The solution is actually quite simple: We just have to get away from the way of thinking of a network with individual components and towards the network as a unified system that gets its intelligence from the applications. Then this intelligence, the controller, recognises what kind of device it is and what it is allowed to do in the network. Instead of configuring devices individually, roles for device types only have to be assigned in a central application - fast, almost self-explanatory and always compliant. The network then does the rest itself.

 

With Cisco Software-defined (SD) Access (SDA for short), the IT world has finally got that. It gives the network a central intelligence that automatically recognises devices, their users and their access rights, i.e. their identity and not just the IP address. In the past, you simply plugged your laptop into an unprotected network socket in the CEO's office and got as many rights as the CEO - that changes with Cisco SD-Access.

 

Cisco DNA Center: Automatic detection, assignment and authentication

Cisco SD-Access is built as a unified system with a central controller, the Cisco DNA Center (DNAC for short) - the brain of the network. The controller can be virtualised, set up via software or as hardware. If each component in the network previously made its own decision, the Cisco controller recognises who is allowed to do what. Honestly: If a company had as many bosses as there are components in the network - there would be an unholy mess. The Cisco DNA Center, on the other hand, provides a meaningful answer to the devices on the network instead of individual hints, segments them and isolates the users from each other. The result is an easy-to-create micro-segmentation that allows employees and devices to do only what they are allowed to do - automatically.

 

ISE: The intelligence of the Cisco network

The most important component here is the Cisco Identity Services Engine (ISE), which queries roles. If I connect a device to such a controlled network, the network sends a request to ISE to identify the device and to query what the device is allowed to do after authentication. This way the controller always knows where which device is on the network and finds the best path through the network. ISE profiles and authenticates the devices. For this, IP address, time, manufacturer, login data and more are taken into account. ISE then assigns the appropriate access rights according to the results.

 

Assigning properties with pxGrid: information exchange among manufacturers

But how does the Cisco network with Cisco SDA know and know the vulnerabilities of the many end devices that exist on the market worldwide? New end devices and their new vulnerabilities are added every day, new security threats emerge and everything is in constant flux. The ISE has platform-fed "intelligence" for this: it receives daily updates from the Cisco Platform Exchange Grid (pxGrid). In this cloud platform, many manufacturers make their context-related information available anonymously. For example, if a manufacturer's device is attacked by a security hole in a virus blocker, the manufacturer publishes this on pxGrid. Cisco SD-Access automatically receives the information - worldwide, the problem is thus discovered within a few minutes and one can react accordingly.

 

Everything in one dashboard, everything automatic

It is also made easier by the Cisco SDA Dashboard. Instead of the seven to eleven dashboards used on average, the Cisco SDA dashboard with ISE intelligence lets you see in just a few minutes where which devices are on the network, what access rights they have and which devices are not compliant. Whereas it used to take hours to commission a new switch, with Cisco SDA all you have to do is connect it to the network and it is automatically provisioned. Cisco calls this Zero Touch Provisioning (ZTP for short) because you no longer have to touch the switch. It only needs power and two to three clicks in DNAC, and it is automatically provisioned, configured and integrated into the system.

 

Distribute roles easily with just a few clicks, detect problems

This saves an enormous amount of money and time, even with larger rollouts! New roles for iPads in meeting rooms, for example, only have to be created once in the DNA Centre, and then all iPads are automatically ready for use. The network loses its complexity because it is tunneled in terms of roles. The role only needs to be created in the DNA Centre - this is also done with a few clicks. In the dashboard, you can see the end devices with their applications and any problems they may have. You can see all the logged-in users and their connections. Problems and their origins are quickly identified, localised and resolved. The tedious search for the source of the problem via CLI access is no longer necessary. The dashboard also presents the problem in a humanly pleasant language. It simply reports: "User has entered the password incorrectly." It could hardly be quicker or more straightforward.

 

Cisco SD-Access for large or small companies?

I'm often asked if you couldn't get the same result with Cisco Meraki. I think for small companies it really is the more suitable solution. But the decisive factors are costs and the required know-how. If Cisco is already in use, it is certainly worthwhile to use Cisco SD-Access. Then the relevant expertise is available.

 

At Bechtle, we always find the right solution for all customers. Sign up today for a no-obligation exchange with one of our experts. We look forward to meeting you.

 

Contact us now

Written by

Miroslav Kosut
Miroslav Kosut
Solution Architect

E-Mail: miroslav.kosut@bechtle.com

    This post was published on Jan 27, 2023.
    Company
    Bechtle Locations
    Career
    Press
    Investor Relations
    Events
    Payment and Delivery
    Help Centre
    Contact
    Support
    Newsletter

    LinkedIn Bechtle LinkedIn Bechtle Schweiz AG

    LinkedIn Bechtle LinkedIn Bechtle direct AG

    YouTube Bechtle YouTube

    Instagram Bechtle Instagram

    Facebook Bechtle Facebook

    Products are sold exclusively to commercial end customers and the public sector.

    Prices in CHF plus VAT.

    Legal Notice Privacy Policy T&Cs
    Support-ID: bdf68a08df
    © 2025 Bechtle AG