
Traditional wan architectures fail modern cloud needs; Mpls offers reliability but costly backhauling, while broadband lacks guarantees and security. Velocloud sd-wan enables direct internet access and agile branch connectivity.
See how Velocloud sd-wan reduces costs and improves performance by intelligently leveraging multiple link types, centralized control, and scalable branch networks to meet cloud and remote-site needs.
Velocloud sd-wan explains how edge, orchestrator, and gateway components provide centralized visibility, transport independence, and automated policy-based control for a flexible, secure, cloud-managed WAN.
Trace the journey of Velocloud SD-WAN from 2012 through VMware and NSX SD-WAN rebrands to Broadcom and Arista ownership. Preserve VCO and VCE naming in the course materials.
Explore Velocloud edge, Velocloud orchestrator, and Velocloud gateway; see how VCEs connect LAN to transport, form Vcmp tunnels, and enable Dempo for traffic steering with zero touch provisioning.
Velocloud orchestrator (VCO) centralizes management, configuration, and monitoring of the sd-wan fabric, using profiles and policies for zero-touch provisioning, telemetry, and software management.
Explore how Velocloud gateway functions as a central hub, exchanging routing with VCE in the control plane and optionally serving data plane traffic for SaaS and cloud apps.
Explore how underlay provides raw transport over MPLS, internet, or LTE. Understand how the overlay forms vcmp tunnels over the underlay to create the sd-wan fabric and dynamic path selection.
Examine Velocloud sd-wan tunnel architecture, where VCE builds vcmp tunnels across MPLS and internet links. See how DMP adds application aware routing, bandwidth aggregation, and dynamic on-demand versus always-on tunnels.
Explore Velocloud sd-wan ports and protocols, including vcmp on UDP 2426 with 500/4500 and ESP protocol 50 for VCE-VCO and VCE-to-VCE, plus management HTTPS on TCP 443.
Dempo (dynamic multipath optimization) dynamically optimizes Arista Velocloud SD-WAN by continuously monitoring links, discovering bandwidth, and steering traffic across underlay transports based on SLA and policy.
Dynamic multipath optimization uses forward error correction and packet duplication across two links, with a jitter buffer, to prevent outages through on-demand remediation and traffic steering during blackout or brownout.
Explore dynamic multipath optimization by examining link steering options—auto, transport group, interface, and wan link—and how mandatory, preferred, and available settings guide failover and traffic for streaming and web traffic.
Explore vcmp tunnel overhead of about 60–70 bytes, compute an effective mtu of 1441 on wan links, and review the vcmp headers and dempo features.
Explore segmentation in Arista SD-WAN by dividing networks into corp, guest, IoT, and OT segments with isolation, using profiles and edge nodes alongside a default global segment.
Create a new test segment and map a vlan, then apply it to quick start and test profiles. Compare global and test segment configurations and review the resulting vlan assignments.
Explore Arista cloud profiles, which define template configurations for single or multiple edge nodes, enabling scalable, zero-touch onboarding, consistent configurations, and flexible overrides.
Explore how a profile bundles device-specific configuration, network settings, Wi-Fi, authentication, DNS, and VLANs with business and firewall policies, and assigns them to edge nodes for segmentation and services.
Explore how to configure and manage a VeloCloud SD-WAN profile in the orchestrator—creating, duplicating, and modifying profiles, customizing VLANs, interfaces, and policies across routing, NAT, VPN, and firewall settings.
Explore how business policies drive SD-WAN optimization through traffic class rules and firewall policies, with hands-on guidance on profiles, edge assignments, and device-specific configuration.
Explore how Arista Velocloud SD-WAN policies—base and firewall—drive traffic flows and security, assignable to edge nodes via profiles, using match‑and‑action rules and QoS traffic classes.
Explore configuring Arista VeloCloud SD-WAN policies in the VCO UI, including creating business and firewall policies with IPv4 match conditions, domain names, protocols, and Netflix.com application rules.
Explore Arista Velocloud network services, centralized templates that enable scalable, consistent deployment across sd-wan, covering non sd-wan destination services, sd-wan destination services, credential services, network management services, and edge services.
Explore non sd-wan destinations outside the sd-wan fabric, including legacy sites, third-party networks, and cloud applications, and how IPsec tunnels connect branch sites or Velocloud gateways.
Discover how the Velocloud orchestrator guides the edge to establish vcmp tunnels with the Velocloud gateway and ipsec tunnels to non SD-WAN destinations.
Configure non SD-WAN destinations via gateway in Velocloud, create and enable AWS VPN gateway tunnels, add site subnets, attach to profiles, and configure BGP.
Learn how SD-WAN destination via edge uses IPsec tunnels from Velocloud edge to non SD-WAN destinations like Office 365, Salesforce, or data centers, enabling direct internet access (Dia) benefits.
Configure non sd-wan destination via edge service in the vco ui, creating a test_edge with IPsec, Ike version two router based vpn, and subnets, then apply to a profile.
Create api credentials to access the SD-WAN orchestrator or VCO, including tenant id, client id, and client secrets, for iaas azure or cloud-based zscaler subscriptions.
Configure api credential services and set up IaaS-based Microsoft Azure and cloud-based Zscaler subscriptions by entering tenant ID, client ID, and password, then save changes.
Learn how cluster and hub network services group edge nodes into a single logical unit to boost resiliency and hub capacity, with auto rebalance managed by VCO.
Configure network services for clusters and hubs in SD-WAN, form a test cluster with two devices, promote edges to hubs via cloud VPN, and apply to a profile.
Configure NetFlow to monitor edge traffic and export IP flow information to collectors. Use collectors and filters with match criteria and actions to govern which flows are recorded.
Configure NetFlow services in Arista VeloCloud SD-WAN by creating collectors and filters, applying NetFlow to profiles, and saving changes to start monitoring flows.
Configure public or private dns in Arista Velocloud using the dns mask service to query multiple servers and select the fastest response, with ipv4 and ipv6 options.
Configure DNS services in the VeloCloud sd-wan network services tab, choosing public or private DNS, naming the service, assigning an IP, and applying it to a profile before saving changes.
Configure private network name services to ensure overlay tunnels form only between interfaces with the same private network name, differentiating multiple mpls networks and preventing cross private link tunnels.
Configure private network name services, assign the private net x y z to an edge interface, and apply the private link to form an overlay tunnel with a matching name.
Enable IPv6 prefix delegation tags to assign IPv6 prefixes to velocloud edge interfaces and hosts by pairing wan and lan tags, using dhcp prefix delegation with a 64 prefix length.
Create a prefix delegation tag in network services, then assign it to WAN and LAN interfaces on an edge node, enabling IPv6 DHCP prefix delegation and saving changes.
Explore authentication services in Arista Velocloud SD-WAN, including configuring IP addresses and authentication codes. Learn how these services authenticate users to access network resources within 22.1 profile and Velocloud UI.
Configure a radius authentication service in the cloud ui, defining test_authentication with the radius server 10.1.1.50, ports 1812/1813, then assign this authentication service to the profile's edge authentication settings.
Explore virtual network functions (vnf) on the Velocloud edge node, enabling firewalls, load balancers, and WAN optimizers as software-based services managed via a centralized server.
Configure a VNF service for a Fortinet firewall on the Velocloud edge, set the manager IP, credentials, image version, and keys, then deploy and save changes.
Examine Arista Velocloud edge models, focusing on the 640 for large branch locations, with eight interfaces, up to 10 gig speeds, VNF, 1.15 million flows, 128 segments, and high availability.
Explore Arista Velocloud branch site topologies—bronze, silver (options 1 and 2), and gold—covering VCE, traditional routers, internet and MPLS links, and layer 2 and layer 3 switches.
Explore branch site topology for small locations in sd-wan deployments, with a VeloCloud VCE device, 1–2 internet links, and no MPLS, where the VCE acts as default gateway and firewall.
Explore the silver site topology option 1 for Arista VeloCloud sd-wan, with a vce between the internet link, the mpls path, and layer 3/2 switches.
Explore the silver site topology option two, where the VCE sits between devices, links to internet and MPLS, and applies policies to route traffic with HSRP/VRRP gateway redundancy.
Discover gold site topology for large branches and regional hubs, with dual uplinks, vce and ce devices, layer three switches, and dynamic routing via ospf or bgp.
Configure the Velocloud orchestrator from a seed ISO image, define credentials and interface addresses, and set up the basic underlay network and gateway topology for VCO initial boot.
Install the virtual cloud gateway (vcg) into the Velocloud sd-wan environment, boot VM, activate the VC with the VCU key, then set up a gateway pool and create the customer.
Activate a VeloCloud VCE using CLI or GUI via LAN or Wi‑Fi, configure VLANs and IPs, and enable zero-touch provisioning with activation emails and a VCO key.
Explore a four-site Velocloud sd-wan topology with Delhi, London, Paris, and New York data center, two VCs, two ISPs, and overlay subnets connecting VCO, VC, and VCE.
Configure ip addresses on VCE interfaces using dhcp or static, manage per-device profiles, and assign vlan1 and svi IPs while handling G4 interfaces across devices.
Access Velocloud edge devices via the orchestrator's remote diagnostics, login through the diagnostics tab, and run commands to view interface status, tunnels, and routing.
Enable cloud VPN to activate overlay routing across Velocloud gateways, establishing persistent Vcmp tunnels that advertise and exchange prefixes between Delhi, London, and Paris subnets.
Enable dynamic branch-to-branch vpn tunnels to connect Delhi and London, reducing latency for traffic. Route the first packet via the gateway, then traffic uses the direct tunnel once established.
Learn to configure a hub site for permanent, static VPN tunnels from multiple branches, enabling stable hub-to-branch and conditional branch-to-branch communication with dynamic options.
Configure a VCE as a hub gateway to route branch traffic through a hub, enabling cloud VPN and branch-to-branch dynamic VPN with static tunnels.
Learn how to change wan link types on Velo edges, distinguish private and public links by RFC 1918 ranges, and enable vcmp tunnels via cloud vpn with user defined links.
Learn to enable ospf globally via Velocloud profiles, enable on vlan one SVIs, advertise loopback addresses, and redistribute overlay prefixes, while understanding differences from traditional routers.
Learn to enable OSPF on routed interfaces in Arista VeloCloud SD-WAN, moving IP addresses from VLAN 1 to routed ports, and configure OSPF area zero with prefix advertising.
Block and advertise the 1.1.1.1/32 prefix using OSPF to illustrate inbound and outbound route manipulation across the Delhi, Paris, and London edges.
Explains the default redistribution between OSPF and Velocloud VRRP, shows how to enable mutual redistribution, and discusses OSPF metric types E1 versus E2 and defaults for default routes and summarization.
This lecture demonstrates route summarization in Velocloud using OSPF, combining two /24 networks into a /23, and advertising the summary via redistribution while comparing E1 and E2 metrics.
Learn to configure static routes in the Velocloud overlay, advertise them into VQP, and redistribute them into OSPF across Delhi, London, and Paris edges to enable reachability.
Configure a default static route at Delhi, replace the old static route, and validate redistribution from VCR to OSPF, while testing from Paris with ping and diagnostics.
Learn to configure ibgp on VeloCloud edge, set up asn 10000, advertise loopback 11 with 11.1.1.1/32 into ibgp, and redistribute into ospf on the london vce.
Configure eBGP between the London VCE and Delhi switch, ASN 10,000 and 12,000, advertising loopback 12.1.1.1/32. Compare OSPF and BGP, noting how admin distances influence route selection and rib status.
Learn to advertise a loopback 99.1.1.1/32 via a network statement in BGP on VeloCloud Edge, and see how disabling redistribution from connected routes reveals the network statement’s impact.
demonstrate OSPF to BGP redistribution on the Velocloud edge, advertising loopback zero into BGP with a seed metric, and explain overlay prefix redistribution and loop avoidance.
Apply BGP route maps on veloCloud edge to adjust attributes of specific prefixes by inbound filters, changing local preference, MED, and as-path prepend while preserving other routes.
In today’s enterprise networks, traditional WAN architectures are no longer enough. Businesses are rapidly adopting SD-WAN to improve performance, simplify operations, and securely connect users to cloud applications. Among the leading solutions in the market, Arista VeloCloud SD-WAN stands out for its scalability, flexibility, and cloud-first approach.
This course is designed to take you from zero to expert in VeloCloud SD-WAN, giving you the skills and confidence to design, configure, and troubleshoot enterprise-grade SD-WAN deployments. Whether you are preparing for a career upgrade, certification, or real-world projects, this course is packed with theory, hands-on labs, and real-world insights.
What You’ll Learn:
Introduction to Arista VeloCloud SD-WAN
Why Traditional WAN Architectures Are No Longer Enough
Business Challenges That Drive the Need for SD-WAN
How VeloCloud SD-WAN Solves the Problem
Journey of VeloCloud SD-WAN
Arista VeloCloud SD-WAN Architecture
VeloCloud Edge (VCE)
VeloCloud Orchestrator (VCO)
VeloCloud Gateway (VCG)
Underlay and Overlay
Arista VeloCloud SD-WAN Tunnel Architecture
Arista Velocloud SD-WAN Ports and Protocols
Dynamic Multipath Optimization(DMPO)_Part-1
Dynamic Multipath Optimization(DMPO)_Part-2
Dynamic Multipath Optimization(DMPO)_Part-3_Link Steering
VCMP, Tunnel Overhead and MTU
Arista VeloCloud SD-WAN Profile, Policy & Segmentation
Arista VeloCloud SD-WAN Segmentation_Part-1
Arista VeloCloud SD-WAN Segmentation_Part-2
Arista VeloCloud SD-WAN Profile_Part-1
Arista VeloCloud SD-WAN Profile_Part-2
Arista VeloCloud SD-WAN Profile_Part-3
Arista VeloCloud SD-WAN Profile_Part-4
Arista VeloCloud SD-WAN Policy_Part-1
Arista VeloCloud SD-WAN Policy_Part-2
Arista VeloCloud Network Services
Network Services
Non SD-WAN Destinations
Non SD-WAN Destinations via Gateway
Non SD-WAN Destinations via Gateway_Config
Non SD-WAN Destinations via Edge
Non SD-WAN Destinations via Edge_Config
Network Services_API Credentials
Network Services_API Credentials_Config
Network Services_Clusters and Hubs
Network Services_Clusters and Hubs_Config
Network Services_Netflow
Network Services_Netflow_Config
Network Services_DNS Services
Network Services_DNS Services_Config
Network Services_Private Network Names
Network Services_Private Network Names_Config
Network Services_Prefix Delegation Tags
Network Services_Prefix Delegation Tags_Config
Network Services_Authentication Services
Network Services_Authentication Services_Config
Network Services_VNF
Network Services_VNF_Config
Arista VeloCloud SD-WAN Topologies
Arista VeloCloud Edge Models
Arista VeloCloud Branch Site Topologies
Arista VeloCloud Bronze Site Topology
Arista VeloCloud Silver Site Topology Option 1
Arista VeloCloud Silver Site Topology Option 2
Arista VeloCloud Gold Site Topology
Build your own Arista VeloCloud SD-WAN Lab
VCO Initial Config
VCG Activation
VCE Activation
Topology Overview
Setting IP addresses on Interfaces
Why This Course?
Concepts First, Configuration Later – I explain complex topics in the simplest way possible, ensuring your fundamentals are crystal clear before we dive into labs.
Real-World Experience – The lessons are based on 14+ years of enterprise networking experience and hands-on SD-WAN projects.
Who This Course Is For:
Networking professionals looking to upskill into SD-WAN.
Engineers and architects preparing for VeloCloud SD-WAN projects.
IT professionals wanting to understand the architecture and operations of a leading SD-WAN solution.
Students preparing for networking certifications who want to strengthen their SD-WAN knowledge.
By the end of this course, you will have the knowledge and hands-on confidence to work with VeloCloud SD-WAN in enterprise environments and accelerate your career in modern networking.
Join me on this journey, and let’s make SD-WAN simple, practical, and powerful !