Fabric thinking: a big L2-ish reach (VXLAN overlay) over a simple routed underlay, with identity and policy decoupled from IP subnets.
SD-Access roles
- Control-plane node: runs LISP mapping — answers “where is this host?”
- Edge node: encapsulates into the fabric, enforces policy at entry.
- Border node: fabric ↔ outside world; border + edge (FGP) for foreign overlays.
- Managed by DNA Center (design → provision → assurance).
Why LISP fits
LISP splits an endpoint into EID (who you are, location-independent) and RLOC (where you are). Hosts move freely; mapping database updates instead of the whole network re-learning.

SD-WAN in the same family
vManage (management), vSmart (control/OMP policy), vBond (orchestration), vEdge routers (data) — underlay agnostic (MPLS + internet + LTE), application-aware path selection over any transport.