CISCOU-1768 - Mini Boot-Camp
CISCOU-1768 - Mini Boot-Camp
Bootcamp
CISCOU-1768
• Cisco Catalyst SD-WAN
Overview
Free SD-WAN Training
Agenda
•
CISCOU-1768 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Catalyst SD-WAN
Overview
Traditional WAN Architecture
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Traditional WAN Architecture vs Today’s WAN
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Cisco Catalyst SD-WAN
On-Premises
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Cisco Catalyst SD-WAN Features
Physical or virtual secured Redundant management Zero-touch provisioning in
routers in cloud or on premises minutes, not days
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Cisco Catalyst SD-WAN Solution Overview
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
SD-WAN Validator
Orchestration Plane
• Virtual machine
• First point of authentication
• Distributes list of Controllers,
Managers to all WAN Edges
• Assists with NAT traversal
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
SD-WAN Controller
Control Plane
• Virtual machine
• Distributes data plane policies
• Implements control plane policies
• “Brain” of the solution
• Like BGP route reflector
• Manages secure data plane
between WAN Edge routers
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
SD-WAN Manager
Management Plane
• Virtual machine
• Single pane of glass GUI
• Centralized provisioning,
troubleshooting and monitoring
• Configuration standardization
• Policies and templates
• REST, NETCONF
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
SD-WAN Edge Router
Data Plane
• Physical or virtual
• Viptela or IOS XE
• Zero Touch Provisioning
• Establishes secure fabric
• Implements data plane
policies
• Exports performance
statistics
• Supports BGP, OSPF, RIP
EIGRP, Static routing,
VRRP
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Overlay Management Protocol (OMP)
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Transport Locators (TLOCs)
Controller
Wan
Edge
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Transport Locators (TLOCs)
Controller
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Transport Locators (TLOCs)
Controllers advertise
Controller TLOCs to all WAN
Edges* (default)
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Transport Locators (TLOCs)
Controllers advertise
Controller TLOCs to all WAN
Edges* (default)
Full-Mesh SD-WAN
Fabric (default)
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Fabric Operation Walkthrough
OMP Update:
OMP
Controller ▪ Reachability – IP Subnets, TLOCs
▪ Security – Encryption Keys
DTLS/TLS Tunnel
▪ Policy – Control/Data/AAR Policies
IPSec Tunnel
OMP OMP
BFD Update Update
Policies
OMP OMP
Update Update
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cloud OnRamp for SaaS – DIA and Gateway
• Cloud OnRamp for SaaS continuously
monitors “edge to SaaS” performance
on both DIA and backhaul paths
• Picks best performing path based on
performance metrics (loss & delay)
ISP2
Loss/
• Automatic failover in case of
Latency
Best Performing performance degradation
Regional Hub • Fully automated
!
ISP1 • Supports 14 apps + custom application
option with NBAR
SD-WAN
MPLS
Fabric
Remote Site
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-WAN Tunnel
SD-WAN Manager
VPC
VPC vNet
=
Site to Site Site to Site
=
SD-WAN Tunnels SD-WAN Tunnels
Cloud Hub Cloud Hub Cloud Hub
SD-WAN Tunnels
Enterprise site
Enterprise site
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Catalyst SD-WAN Integrated Security
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
SD-WAN Cloud Security with Umbrella SIG
DNS/Web-layer Security
Cisco
Cisco
Umbrella
Umbrella Secure Web Gateway
Cloud-delivered Firewall
DIA
Cloud Access Security
Cisco SD-WAN DIA
Fabric Broker (CASB)
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public
Learn More
Rev Up to Recert with Cisco U. For Free
SDWFND
• Solution Components
• Network Deployment
• Configuration Deployment
• Overlay Routing
• Policies and QoS
5 labs, 22 videos
Promo runs until 16/02 IOS XE – 20.9.1
CISCOU-1768 © 2024 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Thank you