
Syllabus Below :
Section 01 Describe Cisco SD-WAN Architecture and Components
01 Welcome
02 CCNP SDWAN + CCNP Certification introduction
03 Exam Topics
04 SDWAN Architecture
05 SDWAN Components Controllers
06 SDWAN Data plan Devices
07 vEdge Features & terminologies used
08 Transport Locators TLOCs
09 IPSEC Data Plan Security
10 SDWAN vRoute or Service side vpn Routes
11 SDWAN Bidirectional Forwarding Detection BFD
12 Distributed Architecture to accommodate high traffic loads
13 IOS XE SDWAN Choose your best hardware part 01
14 IOS XE SDWAN Choose your best hardware part 02
Section 02 Controller Deployment
15 2.1 Describe controller cloud deployment
16 Describe Controller on-Prem Deployment
17 Entire system bringup process includes these steps
18 2.2a Hosting Platform - Hyper-visor
19 System Bring-up Demo Labs
20 Series of Viptela Bring-up theory followed by Labs
21 Controllers System wide Configuration
22 vManage VPN & Static Route Configuration
23 vSmart & vBond VPN & Static Route Configuration
24 Add Controllers to vManage Dashboard
25 Add CSR to Root CA Server
26 Permanent certificates & install certificates to controllers
27 2.2c Scalability & Redundancy
28 2.3 Configure & Verify Certificates & White-listing
29 2.4 Troubleshoot control-plane connectivity between controllers
Section 03 Router Deployment
30 3.0 Router Deployment
31 vManage Dashboard
32 vManage Dashboard 02
33 Zero Touch Provisioning ZTP Theory
34 ZTP Lab
35 WAN Edge Onboarding
36 Device Configuration Starts from here
37 Lap Topology
38 Device Configuration via vManage
39 What are Device Configuration Template
40 Feature Template Creation Part01
41 Feature Template Creation Part02
42 Apply Feature Template
43 CLI Template with Variables
44 Template Creation Planning
45 OMP TLOC Begins Here ..
46 Verification Commands
47 what is OMP ?
48 OMP Route Types
49 OMP Routes Verification
50 OMP & TLOC Attributes
51 OMP Best Path Selection
52 OMP Route Redistribution
53 TLOC-Extension Theory
54 TLOC Extension Lab
Explore a full featured Eve-NG home lab for CCNP/CCNA and SD-WAN practice, with 16 switches, 20 routers, and VEdges and VManage releases 18.4, plus exam sections.
Understand the sd-wan architecture, detailing the orchestration vbond, management plane with vmanage clusters, control plane with vsmart, and data plane devices (vedge) forming ipsec tunnels, plus omp for updates.
Explore the sd-wan controllers: vbond orchestration plane, vmanage management plane, and vsmart control plane. Learn how secure bring-up, OMP-based control, TLS tunnels, and centralized provisioning shape a resilient fabric.
Explore sd-wan data plane devices with application recognition (Cosmos, nbar), application visibility control, app-aware routing and firewalling, OMP routing, and zero-touch provisioning.
Explain the vedge features and terminologies, including underlay TLoc and IPsec, overlay OMP and Viptela route, and how vSmart uses TLoc attributes to map transports to prefixes.
Explore transport locators (tlocs) in sd-wan, including how vSmart uses OMP to advertise and redistribute tlocs, the color abstraction for transport, and IPsec connections across transports and sites.
Discover how sd-wan uses vsmart to manage ipsec keys, reducing key exchange complexity and forming ipsec tunnels automatically with aes-256 encryption and udp encapsulation.
Learn how SD-WAN uses vroute (OMP/service side VPN route) to exchange prefixes via vSmart, advertising service side routes, service routes, and transport locator routes (tlocs) for policy decisions.
Explore bidirectional forward detection (bfd) in sd-wan, tracking tunnel liveliness with hello and poll intervals, buckets, and a multiplier to reveal loss, latency, and jitter for app-aware routing.
Analyze a distributed sd-wan architecture that blends physical and virtual devices, from VH 100 to ESR platforms, selecting hardware by branch bandwidth and comparing ios xe with viptela os.
Select branch hardware by throughput, comparing Viptela devices, IOS XE platforms, and virtual appliances for sd-wan. Virtualization enables third-party vnfs and service chaining, moving from cli toward gui and api.
Assess ios xe sd-wan hardware by balancing security features, memory, and cores; compare edge devices and asr options, and align with application aware firewalling, amp, ips, Cisco Umbrella integration.
Describe on-prem controller deployment for sd-wan, detailing vmanage, vbond, and vsmart behind firewalls, 1-to-1 nat, transport interfaces, dtls/tls and ipsec tunnels, and certificate and whitelisting.
Master the complete Cisco sd-wan bringup workflow from hypervisor installation to certificate management, including zero-touch provisioning and configuring Vmanage, Vbond, and vSmart edges.
explain hardware requirements and steps to install the os on the hyper-visor for Vmanage, vSmart, and Vbond, including three vnic for Vmanage and its database data store.
Train students to bring up the system for sd-wan by installing controllers, applying minimum system-wide and VPN-wide configurations for Vmanage, Vbond, and VSmart, establishing reachability, and enabling certificate-based mutual authentication.
Deploy the viptela control plane by installing the OS, configuring VPN zero and static routes, registering vbond, vmanage, and vsmart in vmanage, and initiating the CSR certificate workflow.
Configure the vbond and vsmart vpn interfaces with manual IPs, using the local keyword for vbond, then set a static route and verify inter-controller reachability via ping.
Log in to the Vmanage dashboard, add controllers (vbond, vsmart, and Vmanage), and configure dtls or tls as available, then generate CSRs for certificates.
Generate CSRs for Vmanage, vbond, and vsmart, upload them to the root CA, then use OpenSSL to create permanent keys and verify certificates.
Learn scalable redundancy strategies for Cisco SD-WAN, including vbond DNS-based failover and vSmart grouping. Explore Vmanage clustering, OMP control planes, VRRP, IGP, and transport locator extension for fabric resilience.
Configure and verify certificates and whitelisting to establish secure dtls or tls tunnels between vbond, vmanage, vsmart, and edge devices with TPM, using mutual authentication, PKI 2048-bit keys, and AES-256.
Troubleshoot control-plane connectivity between controllers by verifying system wide configuration, VPN zero, and certificate organization name, ensuring IP reachability to vbond, and using vmanage CLI or GUI.
Explore router deployments for data centers and branches, including zero-touch provisioning, plug-and-play onboarding, and high-availability using the TLoc extension, OMP, and underlay/overlay verification with vmanage, vsmart, and vbond setup.
Explore the vmanage dashboard to monitor fabric health and device status, view real-time application analytics, and drill into per-device dashboards for loss, latency, jitter, and tunnel metrics.
Explore zero touch provisioning for Cisco SD-WAN, where edge devices auto-configure and join the fabric via vbond and vmanage, using DHCP, DNS, and templates.
Perform ZTP for Cisco SD-WAN by attaching the device in Vmanage and uploading a template from CSV, then validate WAN, DHCP, DNS, and OMP with IPsec and TLOC.
Learn the end-to-end sd-wan device onboarding workflow, from v1 authentication to vmanage and vsmart control plane provisioning, with smart accounts, licenses, plug-and-play portal, and deployment options automated or manual.
Use feature templates to configure devices across data centers and branches. Create the template once and push to branches or data centers, for mixed, dual, or single deployments.
Configure sd-wan devices through vmanage using cli and feature templates, building reusable objects and policies for system wide, vpn wide, and policy settings across vpn zero, management, and transport.
Learn how device configuration templates enable standardization and compliance across the network. Use Vmanage to push feature-based and device-specific templates via netconf, while restricting local changes.
Learn to plan and create Cisco SD-WAN feature templates for a branch, extract device parameters from the running configuration, and assemble small templates (system, aaa, logging, vpn, policies) before deployment.
Create and attach feature templates in Cisco sd-wan using vmanage, populate variables from excel or edits, and verify configuration with difference checks and rollback safeguards.
Create and manage Cisco SD-WAN templates in vmanage, validate and push configurations, and use variables for dynamic values across devices, with change management and template copies.
Classify branch sites and define variables for templates, including hostname, site ID, mpls, internet ip, gateway, and OSPF, then use excel-driven templates to ensure consistency and standardization across deployments.
Verify data plane tunnels and underlay and overlay communication, study the TLOC extension and TLOC routes in OMP, and prepare for overlay management lab work.
Verify the sd-wan setup by checking the control connection with show control connection, inspecting local properties and certificate status, and reviewing the connection and data-plane ipsec tunnels and bfd sessions.
OMP is the overlay management protocol between vSmart peers that controls the underlay and overlay. It enables overlay orchestration, service chaining, traffic engineering, VPN topology management, and routing policy distribution.
Explain the three OMP route types in sd-wan—service-side vpn routes, Tloc routes, and service routes—and how vsmart uses Tlocs and next-hop attributes to distinguish MPLS from internet paths.
Verify all OMP route types—service, TLoc, and VPN—across CLI and GUI, inspecting path IDs, labels, originator attributes, and statuses (chosen, installed, redistributed, unresolved, invalid) to distinguish learned versus self-originated routes.
Master OMP best path selection and loop avoidance through tloc validity, administrative distance, route and tloc preferences, origin; while BFD and vsmart govern tunnel liveliness and hold-down and hello-tolerance timers.
Explores transport locator extension (tloc extension) in Cisco sd-wan, showing how back-to-back cables extend control across transports (mpls and internet) using vpn zero and verified via show control connection commands.
Configure a TLOC extension on MPLS by adding a new interface (gig 0/2) to the transport VPN and applying a variable IP, then push changes to increase control connections.
Explore how VRRP, OSPF, and BGP operate within Cisco SD-WAN using dedicated labs and use cases to compare changes in VRRP with OSPF/BGP and redistribute IGP over OMP.
Verify vr rp behavior in sd-wan by simulating omp failures, monitoring real-time master and backup roles, and using template changes, show debug, and tcpdump to validate vpn traffic.
Learn to configure OSPF in SD-WAN with Viptela, adding a loopback to area zero and redistributing routes via vSmart and OMP using GUI templates.
Configure and verify BGP between edge devices and routers, advertise loopbacks, redistribute BGP into OMP, and apply vSmart policies to prefer data center routes over branches.
verify BGP routes in sd-wan by examining omp routes and vpns, evaluating originator and preference values, and using ipsec topology changes to prefer data centers or hub and spoke arrangements.
Explore sd-wan policy types—control, data, centralized, and localized—and how vsmart enables routing, app-aware routing, and vpn segmentation with hub-and-spoke topologies.
Define and apply viptela sd-wan policies by distinguishing control and data policies, centralized or localized, and attach them to site lists with direction for control plane and data plane.
Learn vSmart policy overview and architecture, including policy direction and the control versus data policy distinction, with configure, apply, and execute steps and core constructs like lists, match, and action.
Create a centralized control policy to block a specific subnet from propagating to branch two in Cisco sd-wan, by matching a prefix list, vpn ten, and site 300, then reject.
Understand vSmart policy execution, including top-to-bottom processing, sequence numbers, and defaults, and apply app route, data policies, service chaining, and route leaks for sd-wan traffic control.
Implement multi topology control policies in sd-wan by configuring hub-and-spoke routes, vpn ten and vpn twenty tlock behavior, and data center firewall redirection.
Demonstrates verifying multi-topology control policies in Cisco SD-WAN by tracing VPN traffic from branches to the data center via the firewall, then shows applying and rolling back policies.
Explore how application aware routing guides SD-WAN decisions and enables direct internet access during outages. Reduce backhaul by letting branches reach cloud resources directly.
Define app routing policies for cloud-based sd-wan, push centralized or localized data policies from vSmart to vEdge, and route applications based on measured loss and latency.
Understand app aware routing in sd-wan using bfd sla class to monitor loss, latency, and jitter in auto mesh ipsec tunnels, with configurable buckets and multipliers.
Learn to build an app routing policy in Viptela fabric, with prefix and VPN lists, loss latency jitter, and VPN match actions, then apply it via site lists and vSmart.
Define app lists, app families, data prefix lists, and site lists; specify class criteria for jitter and loss, then apply outbound app route policy with load balancing.
Extend app-aware routing by configuring vpn, https, and voice/video app lists, defining sequence-based policies on vsmart, and applying the app route policy to branches.
Explore SD-WAN DIA design options that optimize direct internet and cloud access with secure gateways, improve performance, reduce latency and backhauling, and address guest and corporate traffic uses.
Compare centralized data policy and NAT root approaches to deploying DIA, detailing NAT flow and IPsec overlay, and how the DIA tracker reroutes traffic when a tunnel or path fails.
Dia exit design uses separate vrfs for guest and corporate traffic, applying centralized data policy and track to reroute via alternate ipsec tunnels when internet links fail.
Design a single-router dual-internet SD-WAN remote site with guest traffic local exit, employee traffic internet access, NAT on both interfaces, tracker probes, and primary-backup local colors.
Implement direct internet access by configuring a centralized data policy in vmanage, defining VPNs, site lists, and data prefix lists, and applying NAT rules for internet-bound traffic.
Deploy a Cisco SD-WAN data policy in a dia lab by configuring data prefix lists and overlays, then push the policy to edge devices to form an IPsec tunnel.
Learn to copy or import sd-wan policies, edit a non-activated copy with a change ticket, and verify with show sd-wan and nat commands across iOS and Xe.
Explore security and quality of service within sd-wan, including service insertion, application aware firewall, and route leak prerequisites for cross-vpn firewall policies.
Explore how data policy in the Viptela fabric shapes the data plane via service chaining, matching DHCP value ten and routing traffic to the firewall using VPN and site lists.
Protect sd-wan networks by addressing external and internal threats across branch, data center, and cloud edges with a rich security stack on Cisco devices, including DNS, IPS, and URL filtering.
Combine firewall, IPS, URL filtering, and DNS security with next-generation inspection up to layer seven to secure branch traffic and cloud connectivity.
Explore container architecture for Cisco SD-WAN, detailing the control plane, data plane, and service plane, the appnav tunnel, and the installation steps via Vmanage.
Download and upload the Cisco sd-wan virtual image to the vmanage software repository, then create security policies in configuration and security for compliance and guest access.
Discover how to configure Cisco SD-WAN firewall policies in Vmanage, including app-aware inspection and L7 capabilities, zone-based rules for compliance, and route-leaked cross-VPN security.
Create and verify a firewall policy in the same VRF (VPN 40) using data prefix lists and ICMP inspection, and apply it to branches.
Analyze how quality of service policies control packet flow in the Viptela fabric, from ingress classification and ACLs to forwarding classes, queues, and IPsec encapsulation.
Configure access lists and a rewrite policy on VPN ten interfaces, map classes AF1 and AF2 with raid markings, and apply the QoS policy to enable class-based traffic handling.
Learn how to configure a Viptela policer to limit rate and burst, and drop excess packets; apply policies to VPN interfaces in ingress or egress; and verify with show commands.
Learn to redirect traffic between links using viptela qos policers and vSmart data policies, with a 10 mbps commit and 20 mbps burst, monitoring vpn traffic.
Explore how to monitor the sd-wan fabric with Vmanage analytics and view application and vpn insights. Enable analytics, review network health and network capability reports, and download PDF insights.
Discover how rest apis in vmanage enable fast, accurate automation using swagger, json data, and four methods: get, put, post, delete, to manage devices, certificates, monitoring, and troubleshooting.
Fix errors in the API call to check control connections by locating the correct API in vManage and comparing CLI, GUI, and API outputs for controllers, vManage, and vSmart.
Upgrade the vmanage first, then the controllers and finally the edge devices, using the repository images and activation steps, ensuring Vedge is equal or lower than the controllers.
This update introduces eleven new videos with the latest code (20.x) for Cisco SD-WAN, refreshing labs and guiding you to configure features using current ENSDWI concepts.
Understand the sd-wan architecture with decoupled control, data, and management planes, including vManage, vSmart, and vbond. Learn bring-up steps, system wide configuration, vpn zero and 512, and certificate workflows.
Learn to bring up a Cisco sd-wan home lab using vmanage, vbond, vsmart, and edge devices, performing manual and automated certification, plug and play, and orchestration-based baseline configuration.
Learn how plug-and-play onboarding works with BNP, smart account access, and the PNP portal in Vmanage, including creating vbond profiles, attaching devices, uploading variables, and deploying templates and bootstrap configurations.
Build and attach device templates from feature templates to configure system wide settings, VPN templates, and interfaces. Push configurations to devices via netconf and enable redistribution between OSPF and OMP.
Create a generic device feature template by combining small templates, push it from Vmanage using Netconf, then configure VPN ten with OSPF and loopback, and understand OMP tloc routes.
Learn the fundamentals of sd-wan policy design, including omb route selection criteria, centralized vs localized policy, data vs control policy, and the match‑and‑action policy construction applied to edge devices.
Explore implementing Cisco sd-wan control policies and data policies to prefer dc1 or dc2 for branches, using site lists, prefixes, and omp-driven routing.
Learn how VPN membership policy and local route policy control IPsec tunnels in Cisco SD-WAN, restricting VPN ten and VPN twenty, with netconf-based local policy.
The Implementing Cisco SD-WAN Solutions (SDWAN300) v1.0 course gives you deep-dive training about how to design, deploy, configure, and manage your Cisco Software-Defined WAN (SD-WAN) solution in a large-scale live network, including how to migrate from legacy WAN to SD-WAN. You will learn best practices for configuring routing protocols in the data center and the branch and how to implement advanced control, data, and application-aware policies. The course also covers SD-WAN deployment and migration options, placement of controllers, how to deploy and replace edge devices, and how to configure Direct Internet Access (DIA) breakout.
After taking this course, you should be able to:
Describe the Cisco SD-WAN overlay network and how modes of operation differ in legacy WAN versus SD-WAN
Describe options for SD-WAN cloud and on-premises deployments, as well as how to deploy virtual vEdge and physical cEdge devices with Zero Touch Provisioning (ZTP) and device templates
Describe best practices in WAN routing protocols, as well as how to configure and implement transport-side connectivity, service-side routing, interoperability, and redundancy and high availability
Describe dynamic routing protocols and best practices in an SD-WAN environment, transport-side connectivity, service-side connectivity, and how redundancy and high availability are achieved in SD-WAN environments
Explain how to migrate from legacy WAN to Cisco SD-WAN, including typical scenarios for data center and branch
Explain how to perform SD-WAN Day 2 operations, such as monitoring, reporting, logging, and upgrading
This exam tests your knowledge of Cisco’s SD-WAN solution, including:
SD-WAN architecture
Controller deployment
Edge router deployment
Policies
Security
Quality of service
Multicast
Management and operations
Objectives
After taking this training, you should be able to:
Describe the Cisco SD-WAN solution and how modes of operation differ in traditional WAN versus SD-WAN
Describe options for Cisco SD-WAN cloud and on-premises deployment
Explain how to deploy WAN Edge devices
Review the Zero-Touch Provisioning (ZTP) process and examine technical specifics for on-premises deployment
Review the device configuration template and describe new features of device configuration templates
Describe options for providing scalability, high availability, and redundancy
Explain how dynamic routing protocols are deployed in an SD-WAN environment, on the service side and transport side
Describe Cisco SD-WAN policy concepts, which includes how policies are defined, attached, distributed, and applied
Define and implement advanced control policies, such as policies for custom topologies and service insertion
Identify and implement advanced data policies, such as policies for traffic engineering and QoS
Define and implement an Application-Aware Routing (AAR) policy
Implement Direct Internet Access (DIA) and Cisco SD-WAN Cloud OnRamp options
Describe Cisco SD-WAN security components and integration
Describe how to design pure and hybrid Cisco SD-WAN solutions, as well as how to perform a migration to Cisco SD-WAN
Describe Cisco SD-WAN Day-2 operations, such as monitoring, reporting, logging, troubleshooting, and upgrading
Describe Cisco SD-WAN support for multicast
Prerequisites
You should have the following knowledge and skills before taking this training:
Knowledge of Software-Defined Networking (SDN) concepts as applied to large-scale live network deployments
Strong understanding of enterprise WAN design
Strong understanding of routing protocol operation, including both interior and exterior routing protocol operation
Familiarity with Transport Layer Security (TLS) and IP Security (IPSec)
These recommended Cisco offerings that may help you meet these prerequisites:
Implementing and Administering Cisco Solutions (CCNA)
Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)