About This Architecture
SD-WAN overlay with dual MPLS/ISP-2 paths and Cisco Secure Access cloud firewall protects a 20-floor campus LAN spanning three distribution zones. Traffic flows from Internet through Secure Access PoPs and SDWAN edges into active/standby Firewall-A/B, then to redundant Catalyst 9500 core switches managing six VLANs across 25 access switches per floor. This architecture delivers carrier-grade availability, granular segmentation for corporate, voice, wireless, management, IoT, and guest traffic, and cloud-native security without on-premises inspection bottlenecks. Fork and customize this diagram on Diagrams.so to model your own multi-floor topology, adjust VLAN counts, or swap Cisco components for alternative vendors. The three-tier distribution design with active/standby pairs at every layer ensures sub-second failover and zero single points of failure.