V SDCA Lab Guide
V SDCA Lab Guide
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an email
to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa Director.
Versa Director can be accessed by opening the Google Chrome browser on the Remote Desktop.
There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
This lab environment is a shared environment. There may be up to 24 students in the environment.
Each student has their own remote desktop, but the Versa Director is shared. Because of the shared
environment, you may see configuration templates, device groups, workflows, and devices that
other students have created, or that have been pre-provisioned within Versa Director. It is
important that you only modify the configuration components that are assigned to you by your
instructor.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
sample outputs are SAMPLES and represent the information as it appeared during the lab guide
creation. Your output may vary in some ways (some devices may or may not be present, some
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
Look for these results shown in the lab guide. The important thing is that the lab functions in the desired manner.
hints to help you
in the labs
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will allow
you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because of
this, the lab guide contains additional instruction to supplement the student guides.
In the remote landing station, open the Google Chrome browser and log into Versa Director. You
should be placed into the Administration > Appliances dashboard of Versa Director. There are 5 tabs
at the top of the Versa Director user interface. Each of the tabs represents a set of dashboards to
perform certain tasks, such as monitoring devices, managing configuration components on Versa
Director, and creating and managing different components. The currently selected tab is highlighted
automatically:
Many times there The Appliances table of the Administration dashboard lists all of the deployed appliances in
are multiple ways the SD-WAN environment. You can click on a device in the list to navigate directly to that
to navigate
between windows device’s configuration and monitoring dashboard. You can also navigate to the individual
and dashboards. device configuration and management dashboard by clicking the Monitor tab.
The menu on the left displays the main categories of administration information. Wherever you see
a > symbol, this means that the category can be expanded:
The SDWAN Settings dashboard is where the SD-WAN overlay address scheme is defined.
In this lab exercise, you will explore various dashboards of the Versa Director platform and answer
questions related to the areas that you explore.
Task: Navigate to the Configuration tab. Use the GUI to find where configuration templates
are stored.
If you are assigned
Branch 110, the
template created
for your device
probably has a
name related to
Branch 110
Task: Use the GUI to show where the device related configuration is stored.
Task: Use the GUI view the different configuration objects related to the network and SD-
WAN environment.
Navigate to the Workflows tab. In the Workflows tab, examine the different types of
workflows that can be used to create configuration components.
Task: Open the Monitor tab. In the Monitor tab there is a left-side menu and a sub-menu at
the top of the table displayed on the page.
Sub-Menu
Organization Menu
With the SP organization selected, click on the Devices tab to display devices that are
managed by the SP organization.
Click on the Tenant1 organization. With the Tenant1 organization selected, click on the
Devices tab to display devices that are managed by the Tenant1 organization.
Question: What differences do you see between the SP organization view and the Tenant1
organization view within the corresponding Devices tables?
_____________________________________________________________________
_____________________________________________________________________
_____________________________________________________________________
Question: How did the main menu bar change when you opened your branch device?
_____________________________________________________________________
_____________________________________________________________________
Before After
Copyright © 2023 Versa Networks 7
8
Key Differences: Device Context Mode (also called Appliance Context Mode)
Open the Services tab for your device. There are 2 main categories of services that can be
viewed: Services and Networking. Take a few minutes to explore the type of information
available in some of the Services and Networking dashboards.
Task: Click the Home button next to your device name. What happens to the display and
top menu bar?
_________________________________________
_________________________________________
Clicking the Home button takes you back to the main Versa Director system and
dashboards, and exits the device/appliance context mode.
Navigate to the global Administration tab in Versa Director (make sure you are no longer in
the Device/Appliance Context mode). In the Administration tab, locate the Director User
Management menu on the left side and expand the menu. Select the Provider Users from
the menu.
Do you remember Question: What is the Landing Page configured for your user?
what dashboard you
were presented with
when you first _____________________________________________
logged on? _____________________________________________
Click on the Locked Users menu item. This is where user accounts that have been locked
out of the system due to repeated wrong passwords are listed. To unlock a user, you select
the user from the list and click the unlock button in the top right. Currently there shouldn’t
be any locked users on the list.
Unlock users
Expand the System menu. In the System menu. Explore each of the highlighted areas to see
what information can be found there.
The Analytics tab opens the Versa Analytics dashboard. Currently there is a single Versa
Analytics node deployed in the network. However, when multiple Versa Analytics nodes
are configured and linked to Versa Director, you can select which Versa Analytics node is
displayed by choosing the node from the dashboard menu.
Currently displayed Analytics Node Organization level Time frame of displayed data
The left menu is divided into 2 main sections: Dashboards and Logs. The Dashboards
display historical statistic information gathered from devices in the SD-WAN. The Logs
section displays the logs that are sent from processes that run on the end devices.
__________________________________________________________________________
__________________________________________________________________________
__________________________________________________________________________
__________________________________________________________________________
Select the System dashboard. What information is shown on the main System
dashboard?
______________________________________________________________________
______________________________________________________________________
STOP STOP! Notify your instructor that you have completed this lab.
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an
email to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa
Director. Versa Director can be accessed by opening the Google Chrome browser on the Remote
Desktop. There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
sample outputs are SAMPLES and represent the information as it appeared during the lab guide
Look for these creation. Your output may vary in some ways (some devices may or may not be present, some
hints to help you
in the labs
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
results shown in the lab guide. The important thing is that the lab functions in the desired
manner.
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will
allow you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because
of this, the lab guide contains additional instruction to supplement the student guides.
Please refer to the Lab Access Guide for instructions on how to connect to the remote lab
environment.
In the remote landing station, open the Google Chrome browser and log into Versa Director. In Versa
Director, open the Workflows dashboard. On the left-side menu there are 3 main categories of
workflows. Expand all 3 categories so that the sub-components are visible. Examine sub-components
in the diagram below.
Each of these categories of objects or components is related to a type of object within Versa Director:
There are already a few workflows saved in Versa Director that were used to create components in
the lab environment. These include:
• A Controller workflow
• A Template workflow for each of the preconfigured templates
• A Spoke Group workflow for each of the preconfigured spoke group types that are used in the hub-
and-spoke labs
• A Device workflow for each of the preconfigured devices in the lab environment.
Again, it is important to remember that these are saved processes, not the templates, controllers, or
devices that the processes create. We will examine this concept as you complete the lab.
Copyright © 2023 Versa Networks 15
16
In the Infrastructure menu, click on Controllers. All of the controller workflows are listed in the
table. Click on Controller1 (which is the only saved workflow) to open the workflow.
Note that the dialog title is “Deploy Controller – Controller-01”. This is because the end result of
completing the workflow is the creation and deployment of a controller.
Question: To what analytics cluster will this controller forward log and statistics information?
_____________________________________________________________________________________
Question: What are the 2 roles that this controller will perform in the SD-WAN?
_____________________________________________________________________________________
This controller is managed by the SP organization. We’ll see later in the lab that sub-organizations that
fall under the SP organization can use this controller. When multiple sub-organizations use a parent
controller, the controller acts as a multi-tenant controller and maintains separate control plane
functionality for each tenant.
The IP address listed is the out-of-band management interface that is used for initial communication
between the Versa Director and the Versa Controller. It is only used for the creation and onboarding
process. Once the controller is provisioned, a separate interface associates with the Control Network is
used for further communication between the head-end components.
Copyright © 2023 Versa Networks 16
17
This controller will be configured as a Staging controller and as a Post Staging controller. The Staging
Controller function allows devices to be onboarded through this controller. The Post Staging Controller
function allows this controller to act as a BGP route reflector, and SD-WAN CPEs will be able to establish
BGP sessions with the controller for control plane information.
Continue to the Location Information tab. The Location Information tab can be used to indicate where
the controller is physically located.
The Control Network tab is where you define the North-Bound interface that is normally used to
communicate with Versa Director and Versa Analytics. If the Versa Controller or Versa Analytics nodes
are not on the same broadcast domain as the north-bound interface, routing can be configured on the
north-bound interface to enable reachability.
The WAN interfaces are the south-bound interfaces that connect to the SD-WAN environment. It is over
these interfaces that CPEs will communicate with the controller. Note that because this controller has
been deployed in a cloud environment, the internal WAN IP addresses and the public WAN IP addresses
of the cloud environment are configured.
Copyright © 2023 Versa Networks 17
18
If you were creating a new controller, a Deploy button would be present in this dialog box, which would
begin the process of building the controller, including all of the Virtual Routers, VRF tables, routing
protocols, encryption profiles, and all other configuration components required to build a fully functional
controller. Because the controller is created before most other SD-WAN components, and other SD-WAN
components rely on configuration parameters of the controller when they are created, a provisioned
controller cannot be modified using the workflow as changes to the controller would impact all other
devices connected to the controller.
In the Infrastructure menu, select Organizations. The primary organization (SP in this example) is created
during the initial Versa Director configuration process. Subsequent organizations (sub-organizations) are
created using the Organizations workflow.
The Organization workflow allows you to define a sub-organization and its associated parameters. Note
that the controller Controller1 is listed in the Controllers tab. This configuration allows the Tenant1 sub-
organization to use the Controller1. If another sub-organization under the SP domain is created, it could
also be allowed to use the Controller1 controller. Other tenant-specific configuration parameters can be
configured as well, including tenant-specific Analytics connectors, the default routing instances that will
be created for devices within the sub-organization, and the supported user roles available to users within
the sub-organization, which allows the parent organization to manage and control what type of access
users within the sub-organization are allowed to be assigned.
Take a few minutes to explore the configuration parameters included in the organization workflow, then
click Cancel to exit out of the workflow.
It’s common for the Controllers and Organizations workflows to be used only once or twice in an entire
deployment, as those components are normally defined and deployed in the initial stages of the SD-WAN
deployment. The workflows that are used frequently are the Template and Devices workflows.
In the Template workflow menu, select Templates. This opens the Device Template workflow table.
Device Template workflows are used to build the base configuration template that a group of devices will
inherit when a device is created in a later step. There are multiple workflows saved that were created
during the initial lab setup. Device Templates that are created using the Device Template workflow are
placed in the Configuration > Templates > Device Templates table in Versa Director, and are stored in the
local Versa Director database.
The template that is created by a workflow inherits the name of the workflow. Continue to the next page
in the lab guide to answer some questions and fill in some details related to this example workflow.
Fill in the following information based on the workflow in your lab, or the image above:
What organization will have access to this workflow and the template that this workflow
creates? ____________________________________________________________________
To what controller(s) will devices that use this template connect? ______________________
The Interfaces tab allows you to define the common interface layout of the devices that will share the
template configuration created by the workflow. Note that the device Port Configuration diagram is a
logical diagram and does not represent the actual physical device – it is only used for port mapping
purposes and basic port parameters.
The LAN interfaces are the customer site facing interfaces at the local site. The Network Name is a user-
defined name, the Organization determines which sub-organization owns the port, the Zones allows the
user to define a specific security zone associated with the interface, and the Routing Instance is auto-
populated based on the routing instance name configured for the organization. The method that devices
will acquire address is specified in the template. However, the actual addressing is configured during the
device creation process, as addressing is device specific.
To assign a port to a role, click on the port and select the role from the popup window. You can also
change the assignment of a port by clicking on a port that already has an assignment.
The Tunnels tab allows you to specify direct internet access or SD-WAN gateway functions on devices that use
the template created by the workflow. You can also configure site-to-site tunnels for non-SD-WAN tunnels
between devices.
The Routing template allows you to define base routing protocol parameters if desired. When routing
protocol information is configured in the workflow, the workflow process automatically creates the route
redistribution policies required to advertise the local routing information – and routes learned through
the workflow-created routing processes – to remote sites in the SD-WAN.
The Inbound NAT tab allows you to create static destination-NAT to allow outside resources to reach
internal NATed devices.
The Services tab allows you to define what services will be active on the device. The services
Enabling the services
in the template
themselves are not created in the Workflow. The services are activated in the workflow,
workflow allows you which instructs the workflow to create the configuration hierarchy necessary to add the
to configure the services later by defining the services within the template that will be created. If you do not
services in the
resulting template.
enable the services in the workflow, the corresponding configuration hierarchy will not be
created in the template.
The Management Servers tab allows you to define parameters such as NTP servers, Syslog Servers, and
other management server connectivity that will be common among all devices that use the resulting
template.
This workflow is used to reset the Base-Template device template throughout the lab! You will have the
opportunity to create your own template workflow next!
Click Cancel to close the workflow dialog, then select Yes from the popup.
Copyright © 2023 Versa Networks 23
24
Next you will explore the Devices device template. The Device workflow is used to create the individual
devices in the network. Devices created by the Device workflows are added to the Administration >
Inventory > Hardware table in Versa Director.
Select Devices from the Devices workflow section. You will see several device workflows in the table.
These device workflows were used to create the devices in the pre-configured lab environment. In this
part of the lab you will examine the properties of one of the pre-configured device workflows.
Select the Hub device workflow in the table. This will open the workflow that was used to create the Hub
device.
The Basic tab of the device workflows is used for the base parameters. The device that is created in the
Hardware Inventory will inherit the name of the device workflow.
In most situations, the Global Device ID chosen by Versa Director is used to avoid overlapping device IDs
within other organizations, as the Global Device ID must be unique on Versa Director. The Serial Number
is the software or hardware serial number of the device. The Subscription properties can be left at the
default values, in which case the subscription values in the template to which the device is linked will be
used. If you wish to assign different subscription values to the individual device, you may do so here.
The Device Groups parameter is used to link the device to a template. If a device group needed to link the
device to a template does not exist, the +Device Group shortcut will open the Device Group creation
dialog, where you can create the desired device group without leaving the Device workflow.
You must enter a The Location Information tab allows you to enter device location information. The final location
Country value. is based on Latitude and Longitude values that are calculated from the address information. The
Other values are
optional, but the
more detailed the address information, the more accurate the latitude and longitude values will
more specific you be. This information is used to display the device on maps in the Monitor and Analytics
are, the better. dashboards.
The Device Service Template tab allows you to assign service templates to the device directly. In many
instances, the service templates are assigned through the device group. Services templates are
configuration components that are specific to a service, such as Class of Service, Security, or SD-WAN
Policy (application steering). Allowing the administrator to assign a service template directly to a device
allows more flexibility for service assignment.
The Bind Data tab is where you enter device-specific information. When the Bind Data tab is opened, the
template associated with the Device Group (in the Basic tab) is scanned for any variables or values that
the user needs to enter. If the Bind Data tab is empty when you open it, this is usually because the Device
Group configured in the Basic tab is not properly configured, and does not have a corresponding device
template configured. When there is a problem with the device group template assignment, the Bind Data
tab tries to look for template information, but can’t find a related template.
There are 2 ways to enter user-defined information in the Bind Data fields. The first is to enter them
directly in the fields listed in the Device Name field. The scroll bar at the bottom of the Post Staging
Template window allows you to scroll for additional values.
Another common method of entering the bind data is to click on the device name in the table. This will
open a new dialog window that displays all of the required fields.
Click the Hub device name in the table to examine the pre-configured bind data for the device.
IMPORTANT: Do NOT change the bind data information for the Hub105 device!
Click Cancel to close the bind data dialog when you are finished examining the data, then click Cancel
again to close the Device Workflow dialog.
Exercise 5: Practice
In the next lab exercises you will perform the following tasks:
• Create a Template workflow that is named after your branch-id (e.g. Template-Branch01, Template-
Branch02, etc.)
• Create a new device group that links to your newly created template
• Re-assign your existing device to the new device group
• Commit the template in order to re-configure the existing device in the network (using the new
template configuration)
Because this course does not cover deployment of devices, you will not deploy the new device that you
create. However, you will examine the objects created in Versa Director, and you will re-assign your
existing device to the new device group that references the template that you create. You will then
commit the template so that you are familiar with the process of creating a template using Workflows
and applying the template to a device.
In this exercise you will create a new Device Template using a Template workflow. Use a template
workflow to create the template with the following parameters:
Basic Tab:
Organization: Tenant1
Controllers: Controller-01
Bandwidth: 25 Mbps
Example: Template-Branch01
Example Output
Interfaces Tab
Tunnels Tab
Configure Split Tunnels. In the Split Tunnels, link the VRF Tenant1-LAN-VR with the WAN interface INET.
Make the Split Tunnels a DIA type, which allows traffic sourced from the Tenant1-LAN-VR and destined to
a non-SD-WAN destination to use the INET routing instance to forward traffic (Direct Internet Access).
Routing Tab
Services Tab
Enable the SFW services under the Services tab.
Click the Create button to create the workflow and the corresponding device template.
Click on the template that you created with your workflow to open the template and use the values in
the lab to fill in the information below.
vni-0/1
vni-0/2
Question: Why do you think that there are variable names in the interface IP Address field of the
interfaces instead of actual IP addresses?
__________________________________________________________________________________________
INET
LAN-Network
INET-Transport-VR
Tenant1-Control-VR
Tenatn1-LAN-VR
Open the Services tab of the template and identify the type of security services that are enabled:
NextGen Firewall
services have been
enabled in this
configuration
template
Using the information in the Services tab of the template, fill in the following information:
Location Values
Stateful Firewall > Security > Policies What 2 policies are automatically created?
__________________________________________________
__________________________________________________
Stateful Firewall > IPsec What 2 VPN profiles are automatically created?
__________________________________________________
__________________________________________________
__________________________________________________
Expand the Objects menu and examine the types of configuration objects:
• Compare the newly created Device Template to the running configuration on your device
Steps:
• Open your device in Appliance Context mode (by using the Monitor tab, the Configuration > Devices
table, or through the Administration > Appliances table.)
• Identify the security features configured on your device and compare them with the security features
configured in the device template you just created.
Navigate to the Administration > Appliances dashboard. Locate your device in the Appliances table. Click
on your device to open the Appliance Context mode of your device.
From Appliance Context mode, navigate to the Configuration > Services dashboard and identify which
type of security service is currently active in the device:
Question: Are these services the same services that are available under the template that you
created? _______________________________________________
Steps:
• Create a new device group with the name DG-[Branch name] (e.g. DG-Branch01, DG-Branch02, etc.).
• Assign the template that you created to the device group.
• Reassign your device to the new device group (either through the Devices > Device Group dashboard
or through the Device Workflow for your device)
• Commit the changes
• Verify that the services changed on your device from Next Gen Firewall to Stateful Firewall services.
From the main Versa Director dashboard, navigate to Configuration > Devices > Device Groups.
In the Device Groups dashboard, click the + button to create a new device group.
Assign the template you created earlier to the Post Staging Template field, then click OK to create the
device group.
Question: Does your new device group appear in the Device Group table?_________________________
Question: Does your branch device appear in your device group Members list? ______________________
In the next steps, you will use the Device workflow to assign your branch device to the new device group.
Navigate to the Workflows > Devices > Devices dashboard and locate your device in the Device Workflow
list. Click your device to open the workflow.
Locate your new device group in the Device Groups drop-down menu, and assign your new device group
to the device.
Click the Redeploy button to apply the changes to the Device workflow.
You have successfully update the device information in Versa Director. The next step is to apply the
changes made in Versa Director to your appliance by committing the template.
Click the Commit Template link in the top-right corner of Versa Director.
4
2
Verify the Changes on the Device and Revert back to NGFW Services
In the next lab steps you will:
• Verify that the changes have been applied to your device (security services changed from Next Gen
Firewall to Stateful Firewall)
• Change your template services from SFW to NGFW services using the Template Workflow
• Re-deploy your template with the new services definition
• Apply the template changes to your device
• Verify that the security services changed from SFW to Next Gen Firewall services.
In the Versa Director dashboard, navigate to Administration > Appliances and locate your device in the
appliances table.
Click your appliance in the Appliance table to open the Appliance Context mode of your device.
In the Appliance Context mode of your device, navigate to the Configuration > Services dashboard and fill
in the diagram below:
Question: Were the changes you made applied to the device? _________________________
Next you will change the services available on your device back to Next Gen Firewall services by changing
your template using the Template workflow.
Click the Home button next to your device name to exit Appliance Context mode. This returns you to the
main Versa Director user interface.
In the main Versa Director user interface, navigate to Workflows > Template > Templates to display the
saved Device Template workflows.
Locate your Template workflow in the table and click the workflow to open it for modification.
In your Template workflow, navigate to the Services tab.
When an existing template is changed by updating the Template workflow, Versa Director will prompt
you to confirm/validate the changes by doing a Difference (diff and merge) validation. The changes to the
template will be displayed, and the administrator is required to verify and deploy the changes:
Click Deploy to apply the workflow changes to the template, and to re-write the template data.
Verify the Template Changes, and Apply the Update to your Device
Navigate to Configuration > Templates > Device Templates. Ensure that the Tenant1 organization is
selected in the left-side menu.
Locate and open the device template that you just updated through the Device Template workflow.
In the Services tab of the template configuration, verify that the Next Gen Firewall services are present in
the template.
Navigate to the Monitor > Devices dashboard. Ensure that the Tenant1 organization is selected in the left-
side menu.
Locate your device in the Devices table, and open your device. This places you in Appliance Context mode
for your device (in the same way that clicking your device in the Administration > Appliances table places
you in Appliance Context mode).
From Appliance Context mode, navigate to the Configuration > Services dashboard.
The Stateful Firewall services are still present on the device. Although you modified the template and
verified the changes, the template changes haven’t been committed to the devices that the template is
assigned to.
Click the Home button next to your appliance name to exit Appliance Context mode.
From the main Versa Director user interface, click Commit Template.
From the Commit dialog:
1. Select the Tenant1 organization
2. Select your template from the Select Template drop-down menu
3. Select your device from the device list
4. Ensure that Overwrite is selected
5. Click OK to commit the changes to the device.
4
2
Now that you have committed the template changes to your device, you will verify the changes one
more time.
From the Versa Director user interface, navigate to Administration > Appliances and locate you device
in the appliance list. Click your appliance to open the Appliance Context dashboard.
In the Appliance Context dashboard, navigate to Configuration > Services.
Question: Did the available services change from Stateful Firewall to Next Gen Firewall? _____
1. Navigate to the Workflows > Devices > Device hierarchy to display the saved device workflows.
2. Locate your device workflow in the Device Workflow table and click the workflow to open it.
3. In the Device workflow, set the Device Group to DG-NGFW.
4. Click Redeploy to update your device workflow and save the changes.
To finalize the configuration change, click Commit Template in the top right, select the Tenant1
organization, and the Template-NGFW template from the Commit Template to Devices dialog. Locate
your device in the device groups table, select your device, and click OK to commit the changes to your
device.
STOP STOP! Notify your instructor that you have completed this lab.
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an
email to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa
Director. Versa Director can be accessed by opening the Google Chrome browser on the Remote
Desktop. There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
Look for these sample outputs are SAMPLES and represent the information as it appeared during the lab guide
hints to help you
in the labs
creation. Your output may vary in some ways (some devices may or may not be present, some
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
results shown in the lab guide. The important thing is that the lab functions in the desired
manner.
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will
allow you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because
of this, the lab guide contains additional instruction to supplement the student guides.
Topologies
VERSA NETWORKS LAB GUIDE
In this lab you will perform various tasks. You will begin by examining some pre-configured objects
within Versa Director that will be used to build hub and spoke topologies. A flow of the lab exercises
is:
Examine the Spoke Groups that are pre-configured in the Spoke Groups workflow table
Analyze the LAN routes learned on your device, and the BGP next-hops of the routes.
Create a new device template, named after your username and device ID, that is configured as a spoke
device configuration (you will use a Device Template Workflow to create the new template)
The template will be configured with the S2H-Only spoke group
Create a new device group named after your username and device ID that references the new template
you created
Create a new device group named after your username and device ID that references the new template
you created
Re-assign your device to the new device group using the Device Workflow and redeploy the device
workflow
Analyze the LAN routes learned on your device, and the BGP next-hops of the routes.
Analyze the LAN routes learned on your device, and the BGP next-hops of the routes.
Modify the spoke group in your template workflow to S2SviaH, re-deploy the workflow to recreate the
template, then you will commit the template to your device
Analyze the LAN routes learned on your device, and the BGP next-hops (remote gateway) of the routes.
Topologies
VERSA NETWORKS LAB GUIDE
The Template-NGFW workflow creates a device template that is configured for Full Mesh topology.
The Full Mesh setting creates default BGP policies policies that send all routes to the Versa
Controllers, and that allow all routes received from the Versa Controllers. This creates a forwarding
plane that has visibility of and that can forward to all remote CPE devices.
Topologies
VERSA NETWORKS LAB GUIDE
Click Cancel to close the Template Workflow. DO NOT MAKE ANY CHANGES!
Next you’ll analyze the full mesh reachability by using Versa Director and the Monitor tab
(Appliance Context mode).
From Versa Director, navigate to Administration > Appliances and locate your device in the
Appliances table. Click on your appliance to open the Appliance Context mode of your device.
From device context mode of your device, click on Monitor to open the device monitoring
dashboard. Locate and select the Services tab to open the services monitoring dashboard. You
will be examining the Route service to identify what routes and remote nodes are present and
visible to your device.
Topologies
VERSA NETWORKS LAB GUIDE
You can change which virtual router’s routing table is displayed by selecting the virtual router
from the drop-down menu.
Topologies
VERSA NETWORKS LAB GUIDE
• SPK-SPK-HUB: Configured as a spoke-to-spoke-via-hub spoke group, with hub 105 as the hub
device.
• SK-HUB-ONLY: Configured as a spoke-to-hub-only spoke group, with hub 105 as the hub
device.
• SPKTOSPK-DIRECT-MESHGRP-101: Configured as a Spoke to Spoke Direct spoke group, with
BGP community 101 added to the group.
• SPKTOSPK-DIRECT-MESHGRP-102: Configured as a Spoke to Spoke Direct spoke group, with
BGP community 102 added to the group.
Topologies
VERSA NETWORKS LAB GUIDE
Click Cancel
Cancel to close the dialog without making any changes.
The spoke group has the following same parameter set as the Spoke to Hub Only topology.
However, when a spoke group is designated as Spoke To Spoke Via Hub type, the BGP policies
created by Versa Director for the CPE devices add different community values to routes
advertised by the CPE devices. These new community values allow the hub to re-process and re-
advertise the routes to other devices (with the hub set as the BGP next-hop). These policies are
managed and coordinated by Versa Director automatically, and the administrator does not have
to manage them directly.
Click Cancel
Cancel to close the dialog without making any changes.
Topologies
VERSA NETWORKS LAB GUIDE
The spoke group has the same parameters as the other spoke group types, but adds an
additional BGP community parameter to define the mesh group to which the devices will belong.
All devices assigned to the same mesh group will be able to form point-to-point tunnels between
devices. Devices that do not have the same BGP community assigned will behave as Spoke to
Spoke Via Hub, and will be required to forward traffic through the hub to reach the remote
networks.
Click the +Community Options link to view the BGP community dialog.
BGP Communities consist of 2 parts. The Versa Director user interface allows the administrator
to configure the 2nd part of the community value (the Community ID value show above). This
allows Versa Director to ensure that different organizations cannot assign the same complete
community value to a mesh group, and maintains multi-tenant routing consistency. In the
example, if another organization in a multi-tenant environment assigns the same mesh group
community value of 101, the complete community value will still be unique in the control plane,
as the first part of the BGP community will be organization specific.
Click Cancel
Cancel to close the Community Options dialog without making any changes.
Click Cancel
Cancel again to close the Spoke Group dialog.
Topologies
VERSA NETWORKS LAB GUIDE
1. Navigate to the Workflows > Template > Templates dashboard. From the Templates
workflow table, check the box next to the Base-Template-NGFW workflow. This will enable
the Clone button on the task bar.
2. Click the Clone button to create a clone (copy) of the workflow.
In the Clone Template dialog, rename the workflow to a name that is unique to your user-
id/branch-id and the topology type. e.g. branch110-spoke-hub-template
Change the Device Type to Spoke and select SPK-HUB-ONLY as the Spoke Group.
Recreate
Click Recreate button to save the workflow and to create a new template based on the
workflow parameters.
Topologies
VERSA NETWORKS LAB GUIDE
Create a new device group that is associated with the new template.
1. Navigate to the Configuration > Devices > Device Groups dashboard. Ensure that the Tenant1
organization is selected on the left-side menu.
2. From the Device Groups dashboard, click the + button to create a new device group.
3. Give the device group a unique name based on your node or user ID, and associate the
device group with the device template you created in the previous exercise.
Step 1
Topologies
VERSA NETWORKS LAB GUIDE
Step 2
Step 3
Question: Where do you find the complete list of templates that are associated
with the device group, and that will be used as sources for the final device
configurations?
__________________________________________________________________
__________________________________________________________________
Answer: The Post Staging Template Association table shows all of the templates
that will be used to build the final device configurations. This includes the
Common Template (DataStore) and any service templates that will be applied to
the configuration.
Topologies
VERSA NETWORKS LAB GUIDE
1. Navigate to the Workflows > Devices > Devices dashboard and locate the workflow that is
associated with your device in the table (this is the workflow that was used to create your
device in the pre-staging environment).
2. Click your device workflow to open the workflow for modification.
3. In the Basic tab of your device workflow, assign the new device group you created in the
previous steps to the device.
4. Click the Redeploy button to recreate your device in Versa Director. This will re-configure the
device parameters within Versa Director, but the changes still need to be pushed to the end
device with the Commit Template function.
Steps 1 and 2
Steps 3 and 4
Topologies
VERSA NETWORKS LAB GUIDE
1. Click the Commit Template button in the top-right corner of Versa Director.
2. In the Commit dialog, select Tenant1 from the organization dropdown menu.
3. Select your template from the Select Template dropdown menu.
4. Locate your Device Group in the Device Groups table, and mark the box next to your device.
5. Click OK to commit the template.
Note: Your view may appear different from the example. This will
depend on how many other lab students have created device groups
when you reach this step.
Steps 2 through 5
Topologies
VERSA NETWORKS LAB GUIDE
Steps 1 and 2
Steps 3, 4, and 5
It may take some time for other nodes to be re-configured. You can refresh the route table by
WAIT selecting a different route table in the route table dropdown menu, or by clicking the browser
Refresh button. Wait until remote nodes begin to disappear from the Control-VR routing table
before proceeding, or ask your instructor for instructions on how to continue.
Topologies
VERSA NETWORKS LAB GUIDE
• Each remote LAN in the tenant LAN VR will have a BGP next-hop (gateway address) of a
remote site that is located in the Control VR (SDWAN route).
1. Select the Tenant1-LAN-VR route table from the routing table dropdown menu.
2. Locate the Hub LAN in the routing table (172.16.105.0/24)
3. As other lab members finish completing their configurations, note that the remote LANs
associated with their devices are no longer listed in the routing table (you will have to
refresh the browser window, or you can change the routing table in the dropdown, then
change it back to re-query the device routing table). Once all other nodes have been
converted to Hub-and-Spoke, the Tenant1-LAN-VR routing table should be similar to the
example below.
1
2
Before proceeding with the lab, verify with your instructor that other students have progressed
WAIT to a point where your upcoming changes will be effective. If you proceed prior to the following
steps before other students have completed their lab steps to this point, your output may not
match the following examples.
Topologies
VERSA NETWORKS LAB GUIDE
Topologies
VERSA NETWORKS LAB GUIDE
Question: What configuration parameters change when you set the device to
Spoke-to-Spoke-via-Hub?
__________________________________________________________________
__________________________________________________________________
Topologies
VERSA NETWORKS LAB GUIDE
Steps 2 and 3
1. Navigate to the Administration > Appliances dashboard and locate your appliance in the
appliance table.
2. Click your appliance name to open the Appliance Context mode of your appliance.
3. In the Appliance Context mode of your appliance, navigate to the Services > Routes
dashboard (ensure that the Tenant1 organization is selected on the left-side menu).
4. Ensure that the Tenant1-Control-VR routing table is selected in the routing table dropdown
menu.
Topologies
VERSA NETWORKS LAB GUIDE
Steps 1 and 2
Steps 3 and 4
Topologies
VERSA NETWORKS LAB GUIDE
1. Select the Tenant1-LAN-VR routing table from the routing table dropdown list.
2. In the Tenant1-LAN-VR routing table, identify the remote LANs that are visible to your
appliance.
3. Note the Next Hop associated with each remote LAN.
2
3
Question: Why is the next-hop for all of the remote LANs the same?
__________________________________________________________________
__________________________________________________________________
Answer: The hub site accepted all of the routes it received in the BGP
advertisements sent by the spokes (sites). It then reprocessed the routes based on
the new community values associated with the routes and re-advertised the LAN
prefixes. This process of “recycling” the routes causes the hub device to be the
originator of the LAN subnets, and it is therefore the gateway to reach the LAN
destinations.
Topologies
VERSA NETWORKS LAB GUIDE
1. Navigate to the Workflows > Devices > Device hierarchy to display the saved Device workflows.
2. Locate your device workflow in the Device Workflow table and click the workflow to open it.
3. In the Device workflow, set the Device Group to DG-NGFW.
4. Click Redeploy to update your device workflow and save the changes.
Topologies
VERSA NETWORKS LAB GUIDE
Note: Ask your instructor if you should delete the device group and template workflows,
as you may be able to use the same device group and template for future lab exercises.
STOP STOP! Notify your instructor that you have completed this lab.
• Identify when a device configuration is in sync or out of sync with Versa Director
• Import and Export device configurations
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an
email to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa
Director. Versa Director can be accessed by opening the Google Chrome browser on the Remote
Desktop. There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
sample outputs are SAMPLES and represent the information as it appeared during the lab guide
creation. Your output may vary in some ways (some devices may or may not be present, some
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
Look for these results shown in the lab guide. The important thing is that the lab functions in the desired
hints to help you
in the labs
manner.
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will
allow you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because
of this, the lab guide contains additional instruction to supplement the student guides.
Configuration Management
VERSA NETWORKS LAB GUIDE
In this lab you will perform various tasks. You will begin by verifying that your device configuration is
synchronized with the configuration on Versa Director. A flow of the lab exercises is:
Examine the device Sync State and verify that the configuration is in synch
Examine the Sync State and verify that the configuration is out of sync
Configuration Management
VERSA NETWORKS LAB GUIDE
Please refer to the Lab Access Guide for instructions on how to connect to the remote lab
environment.
In the remote landing station, open the Google Chrome browser and log into Versa Director. In Versa
Director, open the Administration > Appliances dashboard in Versa Director. Locate your appliance in
the Appliances table and check the box next to the appliance, then click the Export Configuration
button to export the configuration to a text file. The file will be saved in the remote desktop
Downloads folder.
IMPORTANT
You are changing the IP address of a port on your device. Be sure you DO NOT CHANGE the WAN
port addresses, as this will impact your ability to communicate with Versa Director.
In the Administration > Appliances dashboard, click on your device name to open the Appliance
Context mode. This will allow you to directly modify the configuration of the device.
In the Appliance Context mode, click the Configuration tab to view the device configuration.
Configuration Management
VERSA NETWORKS LAB GUIDE
Select the Interfaces item in the left-side Configuration menu to display the interface configuration.
Locate the vni-0/2 interface. The vni-0/2 interface is the logical port that is mapped to the local LAN.
Click the vni-0/2 interface to open the interface configuration.
In the vni-0/2 interface configuration window, locate the Unit 0 (sub-interface 0) in the table. Note
the IP address assigned to the interface.
Configuration Management
VERSA NETWORKS LAB GUIDE
In the Edit Sub-Interface window, locate the Static IPv4 Address box. The interfaces in VOS can have
multiple IP addresses assigned to the same interface. Remove the existing sub-interface IP address
and add a new address that is incorrect. You can choose any IPv4 address in the 10.27.xxx.yyy/24
range that is different from the one that is originally configured on your device, then click OK.
Configuration Management
VERSA NETWORKS LAB GUIDE
Because you are in Appliance Context mode, the changes will take place immediately. Continue to
click the OK buttons until you have returned to the main Interfaces dashboard. Verify that your
change was applied in the Interfaces table.
In this part you will reload the saved configuration to your device to reset the change you just made.
This is done through the main Administration > Appliances dashboard.
Click the Home button in the top-left corner to exit Appliance Context mode, then navigate to
Administration > Appliances.
In the Administration > Appliances dashboard, locate your device in the table and check the box next
to your device.
Configuration Management
VERSA NETWORKS LAB GUIDE
After you have marked the box next to your device, click on the Import Configuration button and
browse to the Downloads folder. Locate the configuration file that was saved by the export process
(device-name.cfg file). Click OK and you should see a message that indicates that the configuration file
was imported.
branch01.cfg
After you have marked the box next to your device, click on the Import Configuration button and
browse to the Downloads folder. Locate the configuration file that was saved by the export process
(device-name.cfg file). Click OK and you should see a message that indicates that the configuration file
was imported.
Click your device in the Appliances table to open the Appliance Context mode for your device. In
Appliance Context mode, navigate to Configuration > Networking > Interfaces
Note that 2 IP addresses are present: the misconfigured interface address and the imported (correct)
interface address. This is because the configuration import process acts as a “merge” operation. If
conflicting values are present in the configuration, the imported value over-writes the old value. If
multiple values are supported in part of a configuration, then imported value is added to the
configuration.
Configuration Management
VERSA NETWORKS LAB GUIDE
Open the vni-0/2 interface, then edit the sub-interface that contains the IP addresses.
Select the incorrect address and click the – button to delete the interface.
Click OK until you reach the Interfaces configuration dashboard. Verify that the incorrect interface has
been removed.
STOP STOP! Notify your instructor that you have completed this lab.
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an
email to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa
Director. Versa Director can be accessed by opening the Google Chrome browser on the Remote
Desktop. There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
sample outputs are SAMPLES and represent the information as it appeared during the lab guide
creation. Your output may vary in some ways (some devices may or may not be present, some
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
Look for these results shown in the lab guide. The important thing is that the lab functions in the desired
hints to help you
in the labs
manner.
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will
allow you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because
of this, the lab guide contains additional instruction to supplement the student guides.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
In this lab you will perform various tasks and is an open lab environment. You will not be given specific
tasks or steps to take to accomplish lab tasks. Instead, you will explore Versa Director monitoring
capabilities and Analytics information on your own based on the general guidelines below. You will
begin by analyzing real-time statistics for your device through the Versa Director Monitor dashboard.
A flow of the lab exercises is:
Identify where the security and SD-WAN traffic counters are located
Identify where the SD-WAN statistics and SLA performance statistics are located
Identify and explore the network logs are stored and the information stored in the log files.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
The Monitor dashboard provides real-time statistics and counter information, as well as access to
the routing tables, services, and other information about the device.
Wherever you see an eye icon , this indicates that more details can be viewed by clicking the
icon.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Services Menu
The Services tab provides access to real-time counters and status for many things such as SD-WAN
statistics, session information, security counters and policy hits, interface status and parameters,
routing tables, and routing protocols.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Versa Analytics
The Versa Analytics dashboard provides near-real-time and historical information about the
statistics and logs that are gathered from the network. The information can be sorted and filtered
based on event and statistic properties, as well as time periods. Below are examples of some of the
different Analytics dashboards available.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Logs
The Logs dashboard contains the log entries that are forwarded to Versa Analytics from end devices.
Note: Logs are triggered events, many of which are configured in service policies. Because few
services are currently configured in the lab environment, most of the log categories do not contain
any data.
STOP STOP! When you have finished exploring the Monitor and Analytics dashboards,
notify your instructor that you have completed this lab.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Diagnostic Tools
The Versa Networks lab environment consists of a fixed, pre-configured topology that will allow
you to explore, configure, and manage Versa Networks CPEs by using Versa Director, the central
management and orchestration platform for a Versa Secure SD-WAN solution. After completing
this lab, you will be able to:
• Use the built-in diagnostic tools to test reachability between devices; and
• Configure and run the speedtest function between devices.
In this lab, you will be assigned a single CPE device (Branch device) for configuration and
monitoring.
The lab environment is accessed through Amazon Workspaces. You should have received an
email to allow you to register your Amazon Workspaces account and set your password.
NOTE: It is common for the Amazon Workspaces email to be sent to the spam/junk folder. If you
have not received the registration email, check those folders.
The remote desktop connection opens a remote workstation, where you will use various tools to
navigate and configure the lab environment. The main tool you will use in this lab is Versa
Director. Versa Director can be accessed by opening the Google Chrome browser on the Remote
Desktop. There is a bookmark to the Versa Director device in the Google Chrome bookmark bar.
During certain lab parts, the lab guide will present sample output from the GUI or the CLI. The
sample outputs are SAMPLES and represent the information as it appeared during the lab guide
creation. Your output may vary in some ways (some devices may or may not be present, some
routes may or may not be the same, etc.) Do not be alarmed if your results vary slightly from the
Look for these results shown in the lab guide. The important thing is that the lab functions in the desired
hints to help you
in the labs
manner.
This lab guide will step you through some common tasks that are performed on Versa Director.
After an introductory set of exercises, you will be asked to perform some basic tasks that will
allow you to become more familiar with the environment.
The goal of this and all lab exercises is to help you gain additional skills and knowledge. Because
of this, the lab guide contains additional instruction to supplement the student guides.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
In this lab you will perform various tasks and is an open lab environment. You will be given minimal
guidance on how to perform the tasks. In this lab you will:
Open the Appliance Context mode of your device in order to gain access to the diagnostic tools
Initiate a PING to the WAN interface of the Hub device on the MPLS transport
Initiate a PING to the WAN interface of the Hub device on the INET transport
Initiate a PING to the LAN interface on the Hub device in the LAN routing instance
Initiate a speedtest from your node to the Hub device over the MPLS transport
Initiate a speedtest from your node to the Hub device over the LAN routing instance
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Please refer to the Lab Access Guide for instructions on how to connect to the remote lab
environment.
In the remote landing station, open the Google Chrome browser and log into Versa Director. In Versa
Director, open the Administration > Appliances dashboard in Versa Director.
In this lab part you will navigate to the Appliance Context mode of your assigned node. All
configuration and diagnostic tasks will be performed from the Appliance Context mode.
Navigate to the Appliance Context mode of your device. In the Appliance Context mode of your
device, locate and open the Tools tab in the Monitor dashboard.
Open the Ping utility and initiate an ICMP request to the LAN port of the Hub device (10.27.130.98).
Ensure that you are sourcing the ICMP request from the Tenant LAN VR and the IP address of your
local LAN port.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
From the Ping utility, initiate an ICMP request to the MPLS WAN port of the Hub device
(192.168.19.105) to verify connectivity to the WAN interface of the hub. Be sure to source your ICMP
request from the WAN IP address of your device and from the MPLS transport virtual router.
Navigate to the Hub device configuration by selecting the Hub-105 device from the top-left dropdown
menu.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
From the Hub device Appliance Context, navigate to Configuration > Others > System and locate the
Speed Test Server configuration section. Click the Settings tab to display the currently configured
speedtest server settings.
The speedtest server function can respond to and service speedtest request on the routing instances
on which the server is enabled. On the hub device, the speedtest server function is enabled on the
customer-facing LAN and both transport networks.
Return to the Appliance Context mode of YOUR device by selecting your device from the device drop-
down menu.
From your Appliance Context mode, navigate to Monitor > Tools and select the SpeedTest tool.
In the SpeedTest dashboard, initiate a speed test between your device and the Hub device MPLS WAN
port (10.27.12.130). Ensure that the correct routing instance and interface for the traffic is selected.
The results will be shown after the test is complete.
Diagnostic Tools
VERSA NETWORKS LAB GUIDE
Another way to start a speed test is from the Summary tab of the Appliance Context. Navigate to the
Summary tab and locate the INET interface in the CPE Interfaces table (vni-0/1.0). On the right side of
the table, click the Measure button to initiate a speed test on that link. Fill in the dialog box that
appears and click Request.
STOP STOP! Notify your instructor that you have completed this lab.