Mental model
Cisco sells managed networking in different “shapes”. Each shape has a controller that exposes an API. Cisco objective 3.2 (CCNAAUTO 200-901) names the five you need to compare.
- Cloud-managed: Meraki Dashboard. Cisco runs the controller for you; you log into dashboard.meraki.com.
- Enterprise campus controller: Catalyst Center (previously DNA Center). You run it on-prem (or in private cloud) to manage Catalyst switches, routers, and APs.
- Data center fabric: ACI, controlled by APIC.
- SD-WAN: Catalyst SD-WAN (previously SD-WAN by Cisco Viptela), controlled by vManage.
- Cross-vendor orchestration: NSO (Network Services Orchestrator). Model-driven, speaks NETCONF / RESTCONF to anything.
Comparison table
| Platform | Deployment | Primary use | Auth style | Response format |
|---|---|---|---|---|
| Meraki Dashboard | Cisco cloud | Branch / small enterprise (MX / MS / MR / MV) | API key header X-Cisco-Meraki-API-Key | JSON |
| Catalyst Center | On-prem (your VMs) or private cloud | Enterprise campus (Catalyst) | Token: POST to /dna/system/api/v1/auth/token with user:pass → X-Auth-Token | JSON |
| ACI APIC | On-prem (APIC cluster) | Data center fabric | Cookie after POST /api/aaaLogin.json | XML or JSON |
| Catalyst SD-WAN vManage | On-prem or Cisco cloud | SD-WAN sites | Session + CSRF token | JSON |
| NSO | On-prem | Cross-vendor service orchestration | HTTP Basic / token | JSON or XML (per transport) |
When you pick which
- “Small or mid-size branch, I want zero-touch cloud management” → Meraki.
- “Enterprise Catalyst campus, I want on-prem control + assurance” → Catalyst Center.
- “Data center, I want east-west application fabric” → ACI.
- “Hundreds of branches with VPN overlay across providers” → Catalyst SD-WAN.
- “Service orchestration across many vendors” → NSO.
API shapes at a glance
Meraki Dashboard — the gentlest intro
curl -H "X-Cisco-Meraki-API-Key: $KEY" \
https://api.meraki.com/api/v1/organizations
Returns a JSON array of orgs. REST, URL-based, every call is one line.
Catalyst Center — token first
# 1. Get a token (user:pass -> X-Auth-Token)
TOKEN=$(curl -k -u admin:password -X POST \
https://dnac.example.com/dna/system/api/v1/auth/token \
| jq -r .Token)
# 2. Use the token
curl -k -H "X-Auth-Token: $TOKEN" \
https://dnac.example.com/dna/intent/api/v1/network-device
Two steps every session. Token lives ~1 hour.
ACI APIC — login, keep the cookie
curl -c cookie.jar -X POST -H "Content-Type: application/json" \
-d '{"aaaUser":{"attributes":{"name":"admin","pwd":"password"}}}' \
https://apic.example.com/api/aaaLogin.json
curl -b cookie.jar \
https://apic.example.com/api/node/class/fvTenant.json
Catalyst SD-WAN vManage — login + CSRF token
Two-step similar to Catalyst Center but needs a CSRF token on top. Common pattern in older Cisco web admin tools.
NSO — orthogonal
NSO speaks NETCONF (XML over SSH) natively; RESTCONF (JSON over HTTPS) for scripts. You interact with services and devices, not raw APIs per vendor.
Where each platform fits in your automation story
- Config pushes: Meraki Dashboard, Catalyst Center, ACI, SD-WAN all let you push config changes.
- Monitoring / assurance: Catalyst Center is strongest; Meraki next; ACI for DC fabric health.
- Bulk device onboarding: Meraki (claim serials), Catalyst Center (PnP workflows).
- Service orchestration across vendors: NSO.
FAQ
Is Catalyst Center the same as DNA Center? Yes. Cisco rebranded in 2024. Same product, new name. The URL often still contains dnac and the API paths still start with /dna/.
Is Catalyst SD-WAN the same as Viptela? Yes. Cisco acquired Viptela in 2017; the product became SD-WAN by Cisco, then Catalyst SD-WAN. Same vManage controller.
Can one script control all of them? Technically yes, but there is no unified Cisco “all platforms” SDK. For cross-vendor, cross-platform, use NSO.
What is Intersight? Cloud management for Cisco compute (UCS) and some network products (ACI, SD-WAN, Nexus Dashboard). See cisco-compute-platforms.
