
Syllabus Below :
Section 01 Describe Cisco SD-WAN Architecture and Components
01 Welcome
02 CCNP SDWAN + CCNP Certification introduction
03 Exam Topics
04 SDWAN Architecture
05 SDWAN Components Controllers
06 SDWAN Data plan Devices
07 vEdge Features & terminologies used
08 Transport Locators TLOCs
09 IPSEC Data Plan Security
10 SDWAN vRoute or Service side vpn Routes
11 SDWAN Bidirectional Forwarding Detection BFD
12 Distributed Architecture to accommodate high traffic loads
13 IOS XE SDWAN Choose your best hardware part 01
14 IOS XE SDWAN Choose your best hardware part 02
Section 02 Controller Deployment
15 2.1 Describe controller cloud deployment
16 Describe Controller on-Prem Deployment
17 Entire system bringup process includes these steps
18 2.2a Hosting Platform - Hyper-visor
19 System Bring-up Demo Labs
20 Series of Viptela Bring-up theory followed by Labs
21 Controllers System wide Configuration
22 vManage VPN & Static Route Configuration
23 vSmart & vBond VPN & Static Route Configuration
24 Add Controllers to vManage Dashboard
25 Add CSR to Root CA Server
26 Permanent certificates & install certificates to controllers
27 2.2c Scalability & Redundancy
28 2.3 Configure & Verify Certificates & White-listing
29 2.4 Troubleshoot control-plane connectivity between controllers
Section 03 Router Deployment
30 3.0 Router Deployment
31 vManage Dashboard
32 vManage Dashboard 02
33 Zero Touch Provisioning ZTP Theory
34 ZTP Lab
35 WAN Edge Onboarding
36 Device Configuration Starts from here
37 Lap Topology
38 Device Configuration via vManage
39 What are Device Configuration Template
40 Feature Template Creation Part01
41 Feature Template Creation Part02
42 Apply Feature Template
43 CLI Template with Variables
44 Template Creation Planning
45 OMP TLOC Begins Here ..
46 Verification Commands
47 what is OMP ?
48 OMP Route Types
49 OMP Routes Verification
50 OMP & TLOC Attributes
51 OMP Best Path Selection
52 OMP Route Redistribution
53 TLOC-Extension Theory
54 TLOC Extension Lab
Explore a full featured Eve-NG home lab for CCNP/CCNA and SD-WAN practice, with 16 switches, 20 routers, and VEdges and VManage releases 18.4, plus exam sections.
Understand the sd-wan architecture, detailing the orchestration vbond, management plane with vmanage clusters, control plane with vsmart, and data plane devices (vedge) forming ipsec tunnels, plus omp for updates.
Explore sd-wan data plane devices with application recognition (Cosmos, nbar), application visibility control, app-aware routing and firewalling, OMP routing, and zero-touch provisioning.
Explain the vedge features and terminologies, including underlay TLoc and IPsec, overlay OMP and Viptela route, and how vSmart uses TLoc attributes to map transports to prefixes.
Discover how sd-wan uses vsmart to manage ipsec keys, reducing key exchange complexity and forming ipsec tunnels automatically with aes-256 encryption and udp encapsulation.
Learn how SD-WAN uses vroute (OMP/service side VPN route) to exchange prefixes via vSmart, advertising service side routes, service routes, and transport locator routes (tlocs) for policy decisions.
Explore bidirectional forward detection (bfd) in sd-wan, tracking tunnel liveliness with hello and poll intervals, buckets, and a multiplier to reveal loss, latency, and jitter for app-aware routing.
Analyze a distributed sd-wan architecture that blends physical and virtual devices, from VH 100 to ESR platforms, selecting hardware by branch bandwidth and comparing ios xe with viptela os.
Select branch hardware by throughput, comparing Viptela devices, IOS XE platforms, and virtual appliances for sd-wan. Virtualization enables third-party vnfs and service chaining, moving from cli toward gui and api.
Describe on-prem controller deployment for sd-wan, detailing vmanage, vbond, and vsmart behind firewalls, 1-to-1 nat, transport interfaces, dtls/tls and ipsec tunnels, and certificate and whitelisting.
Master the complete Cisco sd-wan bringup workflow from hypervisor installation to certificate management, including zero-touch provisioning and configuring Vmanage, Vbond, and vSmart edges.
Deploy the viptela control plane by installing the OS, configuring VPN zero and static routes, registering vbond, vmanage, and vsmart in vmanage, and initiating the CSR certificate workflow.
Configure the vbond and vsmart vpn interfaces with manual IPs, using the local keyword for vbond, then set a static route and verify inter-controller reachability via ping.
Log in to the Vmanage dashboard, add controllers (vbond, vsmart, and Vmanage), and configure dtls or tls as available, then generate CSRs for certificates.
Configure and verify certificates and whitelisting to establish secure dtls or tls tunnels between vbond, vmanage, vsmart, and edge devices with TPM, using mutual authentication, PKI 2048-bit keys, and AES-256.
Explore the vmanage dashboard to monitor fabric health and device status, view real-time application analytics, and drill into per-device dashboards for loss, latency, jitter, and tunnel metrics.
Perform ZTP for Cisco SD-WAN by attaching the device in Vmanage and uploading a template from CSV, then validate WAN, DHCP, DNS, and OMP with IPsec and TLOC.
Learn the end-to-end sd-wan device onboarding workflow, from v1 authentication to vmanage and vsmart control plane provisioning, with smart accounts, licenses, plug-and-play portal, and deployment options automated or manual.
Configure sd-wan devices through vmanage using cli and feature templates, building reusable objects and policies for system wide, vpn wide, and policy settings across vpn zero, management, and transport.
Learn to plan and create Cisco SD-WAN feature templates for a branch, extract device parameters from the running configuration, and assemble small templates (system, aaa, logging, vpn, policies) before deployment.
Create and manage Cisco SD-WAN templates in vmanage, validate and push configurations, and use variables for dynamic values across devices, with change management and template copies.
Classify branch sites and define variables for templates, including hostname, site ID, mpls, internet ip, gateway, and OSPF, then use excel-driven templates to ensure consistency and standardization across deployments.
Verify data plane tunnels and underlay and overlay communication, study the TLOC extension and TLOC routes in OMP, and prepare for overlay management lab work.
Verify the sd-wan setup by checking the control connection with show control connection, inspecting local properties and certificate status, and reviewing the connection and data-plane ipsec tunnels and bfd sessions.
Verify all OMP route types—service, TLoc, and VPN—across CLI and GUI, inspecting path IDs, labels, originator attributes, and statuses (chosen, installed, redistributed, unresolved, invalid) to distinguish learned versus self-originated routes.
Master OMP best path selection and loop avoidance through tloc validity, administrative distance, route and tloc preferences, origin; while BFD and vsmart govern tunnel liveliness and hold-down and hello-tolerance timers.
Explore how VRRP, OSPF, and BGP operate within Cisco SD-WAN using dedicated labs and use cases to compare changes in VRRP with OSPF/BGP and redistribute IGP over OMP.
Verify vr rp behavior in sd-wan by simulating omp failures, monitoring real-time master and backup roles, and using template changes, show debug, and tcpdump to validate vpn traffic.
Learn to configure OSPF in SD-WAN with Viptela, adding a loopback to area zero and redistributing routes via vSmart and OMP using GUI templates.
verify BGP routes in sd-wan by examining omp routes and vpns, evaluating originator and preference values, and using ipsec topology changes to prefer data centers or hub and spoke arrangements.
Explore sd-wan policy types—control, data, centralized, and localized—and how vsmart enables routing, app-aware routing, and vpn segmentation with hub-and-spoke topologies.
Define and apply viptela sd-wan policies by distinguishing control and data policies, centralized or localized, and attach them to site lists with direction for control plane and data plane.
Learn vSmart policy overview and architecture, including policy direction and the control versus data policy distinction, with configure, apply, and execute steps and core constructs like lists, match, and action.
Create a centralized control policy to block a specific subnet from propagating to branch two in Cisco sd-wan, by matching a prefix list, vpn ten, and site 300, then reject.
Understand vSmart policy execution, including top-to-bottom processing, sequence numbers, and defaults, and apply app route, data policies, service chaining, and route leaks for sd-wan traffic control.
Explore how application aware routing guides SD-WAN decisions and enables direct internet access during outages. Reduce backhaul by letting branches reach cloud resources directly.
Define app routing policies for cloud-based sd-wan, push centralized or localized data policies from vSmart to vEdge, and route applications based on measured loss and latency.
Learn to build an app routing policy in Viptela fabric, with prefix and VPN lists, loss latency jitter, and VPN match actions, then apply it via site lists and vSmart.
Extend app-aware routing by configuring vpn, https, and voice/video app lists, defining sequence-based policies on vsmart, and applying the app route policy to branches.
Compare centralized data policy and NAT root approaches to deploying DIA, detailing NAT flow and IPsec overlay, and how the DIA tracker reroutes traffic when a tunnel or path fails.
Dia exit design uses separate vrfs for guest and corporate traffic, applying centralized data policy and track to reroute via alternate ipsec tunnels when internet links fail.
Deploy a Cisco SD-WAN data policy in a dia lab by configuring data prefix lists and overlays, then push the policy to edge devices to form an IPsec tunnel.
Explore security and quality of service within sd-wan, including service insertion, application aware firewall, and route leak prerequisites for cross-vpn firewall policies.
Explore how data policy in the Viptela fabric shapes the data plane via service chaining, matching DHCP value ten and routing traffic to the firewall using VPN and site lists.
Protect sd-wan networks by addressing external and internal threats across branch, data center, and cloud edges with a rich security stack on Cisco devices, including DNS, IPS, and URL filtering.
Explore container architecture for Cisco SD-WAN, detailing the control plane, data plane, and service plane, the appnav tunnel, and the installation steps via Vmanage.
Download and upload the Cisco sd-wan virtual image to the vmanage software repository, then create security policies in configuration and security for compliance and guest access.
Discover how to configure Cisco SD-WAN firewall policies in Vmanage, including app-aware inspection and L7 capabilities, zone-based rules for compliance, and route-leaked cross-VPN security.
Analyze how quality of service policies control packet flow in the Viptela fabric, from ingress classification and ACLs to forwarding classes, queues, and IPsec encapsulation.
Configure access lists and a rewrite policy on VPN ten interfaces, map classes AF1 and AF2 with raid markings, and apply the QoS policy to enable class-based traffic handling.
Learn how to configure a Viptela policer to limit rate and burst, and drop excess packets; apply policies to VPN interfaces in ingress or egress; and verify with show commands.
Learn to redirect traffic between links using viptela qos policers and vSmart data policies, with a 10 mbps commit and 20 mbps burst, monitoring vpn traffic.
Explore how to monitor the sd-wan fabric with Vmanage analytics and view application and vpn insights. Enable analytics, review network health and network capability reports, and download PDF insights.
Discover how rest apis in vmanage enable fast, accurate automation using swagger, json data, and four methods: get, put, post, delete, to manage devices, certificates, monitoring, and troubleshooting.
Fix errors in the API call to check control connections by locating the correct API in vManage and comparing CLI, GUI, and API outputs for controllers, vManage, and vSmart.
Upgrade the vmanage first, then the controllers and finally the edge devices, using the repository images and activation steps, ensuring Vedge is equal or lower than the controllers.
Learn to bring up a Cisco sd-wan home lab using vmanage, vbond, vsmart, and edge devices, performing manual and automated certification, plug and play, and orchestration-based baseline configuration.
Learn the fundamentals of sd-wan policy design, including omb route selection criteria, centralized vs localized policy, data vs control policy, and the match‑and‑action policy construction applied to edge devices.
Explore implementing Cisco sd-wan control policies and data policies to prefer dc1 or dc2 for branches, using site lists, prefixes, and omp-driven routing.
Learn how VPN membership policy and local route policy control IPsec tunnels in Cisco SD-WAN, restricting VPN ten and VPN twenty, with netconf-based local policy.
The Implementing Cisco SD-WAN Solutions (SDWAN300) v1.0 course gives you deep-dive training about how to design, deploy, configure, and manage your Cisco Software-Defined WAN (SD-WAN) solution in a large-scale live network, including how to migrate from legacy WAN to SD-WAN. You will learn best practices for configuring routing protocols in the data center and the branch and how to implement advanced control, data, and application-aware policies. The course also covers SD-WAN deployment and migration options, placement of controllers, how to deploy and replace edge devices, and how to configure Direct Internet Access (DIA) breakout.
After taking this course, you should be able to:
Describe the Cisco SD-WAN overlay network and how modes of operation differ in legacy WAN versus SD-WAN
Describe options for SD-WAN cloud and on-premises deployments, as well as how to deploy virtual vEdge and physical cEdge devices with Zero Touch Provisioning (ZTP) and device templates
Describe best practices in WAN routing protocols, as well as how to configure and implement transport-side connectivity, service-side routing, interoperability, and redundancy and high availability
Describe dynamic routing protocols and best practices in an SD-WAN environment, transport-side connectivity, service-side connectivity, and how redundancy and high availability are achieved in SD-WAN environments
Explain how to migrate from legacy WAN to Cisco SD-WAN, including typical scenarios for data center and branch
Explain how to perform SD-WAN Day 2 operations, such as monitoring, reporting, logging, and upgrading
This exam tests your knowledge of Cisco’s SD-WAN solution, including:
SD-WAN architecture
Controller deployment
Edge router deployment
Policies
Security
Quality of service
Multicast
Management and operations
Objectives
After taking this training, you should be able to:
Describe the Cisco SD-WAN solution and how modes of operation differ in traditional WAN versus SD-WAN
Describe options for Cisco SD-WAN cloud and on-premises deployment
Explain how to deploy WAN Edge devices
Review the Zero-Touch Provisioning (ZTP) process and examine technical specifics for on-premises deployment
Review the device configuration template and describe new features of device configuration templates
Describe options for providing scalability, high availability, and redundancy
Explain how dynamic routing protocols are deployed in an SD-WAN environment, on the service side and transport side
Describe Cisco SD-WAN policy concepts, which includes how policies are defined, attached, distributed, and applied
Define and implement advanced control policies, such as policies for custom topologies and service insertion
Identify and implement advanced data policies, such as policies for traffic engineering and QoS
Define and implement an Application-Aware Routing (AAR) policy
Implement Direct Internet Access (DIA) and Cisco SD-WAN Cloud OnRamp options
Describe Cisco SD-WAN security components and integration
Describe how to design pure and hybrid Cisco SD-WAN solutions, as well as how to perform a migration to Cisco SD-WAN
Describe Cisco SD-WAN Day-2 operations, such as monitoring, reporting, logging, troubleshooting, and upgrading
Describe Cisco SD-WAN support for multicast
Prerequisites
You should have the following knowledge and skills before taking this training:
Knowledge of Software-Defined Networking (SDN) concepts as applied to large-scale live network deployments
Strong understanding of enterprise WAN design
Strong understanding of routing protocol operation, including both interior and exterior routing protocol operation
Familiarity with Transport Layer Security (TLS) and IP Security (IPSec)
These recommended Cisco offerings that may help you meet these prerequisites:
Implementing and Administering Cisco Solutions (CCNA)
Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)