StudyToCert

All certifications / ENCOR / Lessons

Cisco CCNP Enterprise core exam (ENCOR) 350-401 v1.2 · Domain 1: Architecture

Enterprise design: two-tier (collapsed core) and three-tier campus, fabric/spine-leaf, cloud vs on-premises

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Enterprise network design is about arranging switches and routers into layers so the network is predictable, easy to grow and quick to recover from failures. Cisco's classic campus model uses three logical layers: access, distribution and core. ENCOR expects you to know what each layer does, when you can merge layers, and how data center and cloud designs differ from the campus.

The access layer is where users, phones, access points and printers connect. It provides port density, Power over Ethernet (PoE), VLAN assignment and edge security features such as port security, 802.1X and DHCP snooping. The distribution layer aggregates many access switches. It is the natural boundary between Layer 2 and Layer 3: it usually hosts the default gateways (with a first hop redundancy protocol), summarizes routes toward the core and applies policy such as access control lists (ACLs) and quality of service (QoS). The core layer is the high-speed backbone that connects distribution blocks, the data center and the WAN edge. The core should do as little as possible other than forward packets quickly and converge fast, so you avoid heavy policy there.

A three-tier design makes sense for a large campus with several buildings, where many distribution blocks need a common backbone. Without a core, every distribution pair would need links to every other pair, which grows as a full mesh and becomes hard to manage. A two-tier design, also called a collapsed core, merges the core and distribution functions into one pair of switches. It fits a single building or a smaller campus, costs less and has fewer hops. The trade-off is scale: when you add more buildings, a dedicated core becomes worth it.

Modern campus designs push Layer 3 closer to the edge. In a routed access design, the access switches run a routing protocol toward the distribution layer, so there are no Layer 2 loops between access and distribution, spanning tree is confined to each access switch, and convergence depends on routing rather than spanning tree timers. The trade-off is that a VLAN can no longer span several access switches.

Data centers usually use a spine-leaf (Clos) fabric instead. Every leaf switch connects to every spine switch, and spines do not connect to each other, nor do leaves. Servers attach to leaves. Any server is always exactly two hops from any other (leaf to spine to leaf), which gives predictable latency and lots of equal-cost paths for east-west traffic between servers. You scale bandwidth by adding spines and scale ports by adding leaves. Overlays such as VXLAN usually run on top of a routed spine-leaf underlay.

Finally, ENCOR asks you to compare on-premises and cloud deployments. On-premises means you buy, house and operate the hardware: you get full control, predictable costs after purchase and data locality, but you carry capital expense, capacity planning and hardware refresh. Cloud (public infrastructure as a service, platform or software as a service) shifts spending to operating expense, lets you scale up and down quickly and removes hardware management, but adds dependence on WAN or internet connectivity, less control over the underlying platform, and ongoing usage-based cost. Many enterprises end up hybrid, with some workloads in each.

Key terms

Access layer
The layer where endpoints connect; provides port density, PoE, VLAN assignment and edge security.
Distribution layer
Aggregates access switches, usually hosts default gateways, and applies policy and route summarization.
Core layer
The high-speed backbone joining distribution blocks, designed for fast forwarding and fast convergence.
Collapsed core
A two-tier design where one pair of switches performs both core and distribution roles.
Spine-leaf
A data center topology where every leaf connects to every spine, giving equal-cost, two-hop paths between servers.
Real-world example

A company with one office building uses a pair of Catalyst switches as a collapsed core, with access switches in each wiring closet uplinked to both. When it opens two more buildings on the same campus, it adds a dedicated core pair so each building's distribution pair needs only two uplinks to the core instead of links to every other building.

Exam tip: If a question describes predictable latency for east-west server traffic and every leaf connecting to every spine, the answer is spine-leaf. If it describes a small site merging core and distribution, it is a two-tier collapsed core.

Check yourself

Why does a large campus add a dedicated core layer instead of connecting every distribution pair directly?

Directly meshing distribution blocks grows as a full mesh and becomes costly and hard to manage; a core gives every block a small, fixed number of uplinks to a common backbone.

In a spine-leaf fabric, how many switch hops separate servers on two different leaves?

Two hops across the fabric, leaf to spine to leaf, because every leaf connects to every spine.

Name one advantage and one drawback of public cloud compared with on-premises.

Advantage: fast elastic scaling with operating rather than capital expense. Drawback: less control over the platform and dependence on connectivity, plus ongoing usage costs.

Study ENCOR for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the ENCOR study plan