
Section 01 :
Lecture 2:
Course Agenda
Lecture 3:
Why Cisco iWAN ?
Lecture 4:
Intelligent WAN Deployment Models & Transport-Independent Design
(Preview enabled)
Lecture 5:
Scenario 1 Provisioning a Dual DC IWAN Environment 01
Lecture 6:
Scenario 1 Provisioning a Dual DC IWAN Environment 02
Lecture 7:
Scenario 1 Provisioning a Dual DC IWAN Environment 03
Lecture 8:
iWAN other 3 Features PC PfR Secure Connectivity
Lecture 9:
IWAN Independent Transport Design
(Preview enabled)
Lecture 10:
DMVPN Configuration Example
Lecture 11:
DMVPN Configuration Verification
Lecture 12:
Intelligent Path Control – Performance Routing v3
Lecture 13:
PfR Components & Deploying IWAN Intelligent Path Control
Lecture 14:
PfR Configuration Verification
Lecture 15:
Direct Internet Access
Lecture 16:
DIA Configuration & Verification
Lecture 17:
DIA Verification 02
Explore intelligent wide area network deployment models and transport-independent design. Compare internet, hybrid, and secure access options with a focus on application routing, firewall, and optimization features.
Configure a dual data-center iwan environment by provisioning the master controller, assigning management IPs, validating settings, and adding devices with internet interfaces, then configure lan and isp interfaces.
Provision a dual data center iwan environment by completing device deployment in data centers one and two, configuring the igp routing protocol, and adding the site prefixes.
Explore a DMVPN hub-and-spoke configuration with yariv, creating transport interfaces for ambulance and internet, attaching tunnel interfaces, and defining hub-to-spoke IP routing and profiles.
Explore the components of performance routing (PfR) and deploy IWAN intelligent path control, including master controller roles (hub master controller and domain controller), branch devices, prefixes, and monitoring policies.
Verify PfR configuration across data center and branch by inspecting domain, policy status, prefixes, and path changes, then trace traffic flow and convergence using the presented commands.
Explore direct internet access from branches, reducing data center traffic, while securing traffic with firewall policies and gateways such as cloud gateways and Cisco Umbrella in a Cisco SD-WAN migration.
Learn to configure and verify direct internet access in a Cisco WAN to SD-WAN migration POC, including interfaces, gateways, policy maps, class maps, NAT, and basic BGP.
Verify translation works by pinging from the LAN interface and inspect policy and class maps to confirm ICMP traffic from source to destination during Cisco WAN to SD-WAN migration.
Explore Cisco's software-defined WAN, including architecture, fabric, and centralized or localized policies. Understand how a central controller and cloud integration enable security, telemetry, and automation across edge devices.
Explore end-to-end sd-wan features, policy tagging and analytics with DNA Center to securely connect branches across on-prem and cloud environments with traffic engineering and unified visibility.
Explore sdwan controller deployment options from cloud and on-prem to service provider and private cloud, along with plug-and-play setup, device registration, and controller profiling for scalable networks.
Establishes a secure SD-WAN control plane by detailing mutual certificate authentication among controllers, devices, and management systems, with certificate types, OTPs, and TPM-based security.
Operate the fabric by establishing control and data planes, managing edge devices with overlay management protocol, exchanging policies and keys via reichsmark and omb, and monitoring liveliness with bfd.
Explore how OMP overlay routing learns, advertises, and selects routes across the fabric by distributing internal and service-side routes via BGP-like attributes, applying policy-driven preferences to determine the best path.
Explore centralized and localized sd-wan policies, distinguish control and data policies, and learn how they are pushed from we manage to edge devices.
Demonstrates policy-based service insertion to redirect traffic through a firewall in a hub-and-spoke and data center VPN setup, including creating, modifying, and activating policies across branches.
Master how to configure an extranet policy to share routes among vpn 20, 40, and 100, using loopback interfaces, prefix lists, and export rules, with verification and troubleshooting.
Explore how data policies govern application traffic and how they differ from control policies, and how destination and source matching enables ambulance traffic prioritization with internet fallback.
Configure a data policy with app-aware routing for audio/video and web apps, create app groups, set primary and backup actions, apply to all branches, and verify on edge device.
Verify the data policy for app-aware routing is declared, applied across all data and branches, and monitor tunnel traffic to validate latency, jitter, and policy effectiveness.
Plan a data center–first sd-wan migration in the lab, deploying controllers with feature templates for scalable configuration, migrating data centers before branches, and implementing omb and vpns.
Book and access Cisco cloud lab for the poc, import or create topology, and deploy the lab to provision the control plane across devices in about one hour.
Bring up additional data center devices by provisioning bootstrap config, installing certificates, updating platform software, applying a site template, and validating control connections in the we manage dashboard.
Demonstrates advertising BGP routes from devices to the SD-WAN, creating separate templates for data center and branches, and configuring redistribution of OMB into BGP with route filters to prevent duplicates.
Learn how internal BGP routes are redistributed into BGP across data centers, configure local policies and tagging, and validate route propagation in a Cisco WAN to SD-WAN migration context.
Migrate branch hardware and software after data center migration, verify and upgrade the router image, then push the Estevan bootstrap configuration template via we manage to complete the branch migration.
Execute the branch bootstrap and authentication steps, install and attach the deployment template, upload variables, and monitor the fabric join as the device comes online.
Plan and execute branch five migration with a cutover to a new internet link, using Estevan traffic routing as a rescue path and bootstrap configuration, root certificate, and BGP verification.
Perform post migration checks by validating BGP configurations between sites and examining learned prefixes. Redistribute routes via a BGP template and verify path reachability.
Analyze pre-migration configuration and hardware options, compare features between solutions, assess deployment models (cloud, on-premises, or hosted), evaluate control plane, licensing, throughput, and visibility for Cisco SD-WAN migration.
Configure a data center migration by provisioning minimum device configurations and attaching templates. Establish a BGP ring between DC devices to join the fabric.
Attach the vSmart template, activate the central policy, and run an automation script to perform verification tasks and validate policy behavior in a Cisco WAN to SD-WAN migration.
Migrate branch five from iwan to sd-wan by applying certificate and bootstrap configuration, converting the device to sd-wan, and enabling controller mode. Apply the branch five template via automation.
Continue onboarding branch five by applying the internet type 2 template, configuring BGP and tunnels, and validating control plane connectivity for the SD-WAN migration from iwan.
Explore per-tunnel QoS verification in a Cisco WAN to SD-WAN migration context, using local policies, policy maps, and interface-level settings to validate bandwidth and tunnel behavior across branches.
IWAN migrations are each very unique to the customer environment. This Course gives general migration steps and guidelines, with configuration example of a case study, for migration from a specific IWAN environment to Cisco SD-WAN.
The scope of this Course includes:
● Section 1 & 2: Provides high level overview of IWAN and SD-WAN architectures
● Section 3: The migration planning section provides the guidelines about the information needed to plan a successful IWAN to SD-WAN migration.
● Section 4: After the requirements are identified in Section 3, this section identifies the common migration steps to follow during migration.
● Section 5: A case study of migrating an IWAN lab setup to SD-WAN. This section provides a walkthrough of migrating an IWAN deployment to SD-WAN by using the guidelines provided in Section 3 and 4.
● Section 6: An overview of advanced use cases for Cisco SD-WAN is presented. Note that customers must validate the migration scenarios, for their specific environment in the lab environment, before migrating production sites .
We will complete the following tasks :
• Cisco SD-WAN Crash Course
• Introduction to the Cisco SD-WAN Policy Framework
• Control Policies and Applications
• Data Policies and Applications
• Application Aware Routing Policies and Applications
• More Policies and Applications
• Tips, Tricks, Scalability and Best Practices
• Conclusion
-> IWAN to Cisco SD-WAN Migration Guide & Using Automation to Simplify IWAN to SD-WAN Migration Lab
IWAN and Cisco SD-WAN Overview
Migration Planning
Migration Deployment Steps ( DC & Various types of Branches )
Customer IWAN to Cisco SD-WAN Migration Case
Cisco SD-WAN Advance Use-cases
TASK 1 : : Get Familiar with Cisco SD-WAN POC Tool - Cisco Test Drive
TASK 2 : Baseline the IWAN deployment
Task 3: Restore, Backup, and Delete SD-WAN Templates and Policies with Sastre
Task 4: DC1-SanJose Greenfield Migration – WAN Edges and Central Policy
Task 5: Onboard and Migrate BR3-LAX-MCBR from IWAN to SD-WAN
Task 6: Onboard and Migrate BR5-BCN-BR2 from IWAN to SD-WAN
Task 7: SD-WAN Assurance and Reporting with Sastre-Pro
Task 8: Sharing and Distributing Sastre-Pro Backups