
Explore how Cisco SD-WAN fundamentals empower enterprises to design efficient WANs that support cloud services, AI, virtualization, machine learning, and the Internet of Things while simplifying operations and reducing costs.
Redefine the wide area network by moving from data center–centric connectivity to cloud and internet-based architectures, highlighting MPLS limits, latency, and security and compliance issues.
Explain why the traditional network design fails to scale, highlighting costly MPLS deployments, per-device policy management, and security and provisioning bottlenecks in modern hybrid clouds.
Learn how sd-wan lowers costs by using hybrid WAN, reducing MPLS reliance, and enabling direct cloud access with broadband, while delivering centralized management, visibility, and security across multi-cloud environments.
Explore how software defined SD-WAN builds a secure overlay over MPLS, broadband, and LTE, enabling centralized management, application visibility, and the separation of the data plane and the control plane.
Explore how the Cisco SD-WAN virtual IP fabric separates transport from server networks, centralizes routing intelligence via the vSmart controller, and enables secure, centralized provisioning with VMANAGE and CMS.
Secure the virtual IP fabric with Cisco Secure Extensible Network. Link V edge routers and Scarlett V Edge Cloud Routers across data centers and cloud platforms.
Explore how four planes—data, control, management, and orchestration—shape Cisco SD-WAN architecture, enabling automated onboarding, central configuration, network topology decisions, and packet forwarding.
vBond orchestrates connectivity across the fabric, enabling mutual discovery of vSmart and vManage, authenticating edge routers via TLS and Atlas Tunnel, and supporting NAT traversal for deployment.
Leverage Cisco vManage, the management plane interface, to configure, provision, troubleshoot, and monitor the SD-WAN, define policies, and use device templates to streamline centralised control plane and edge router configurations.
Explore how vSmart controllers manage the control plane, centrally enforce policies from Vmanage, and influence routing, access control, segmentation, and service chaining across the fabric.
Establish and maintain the control plane with the overlay management protocol between the vSmart controller and edge routers, exchanging route prefixes, next hops, and policy information over secure IPsec connections.
Discover how Cisco edge routers act as data plane elements in a secure extensible network fabric, connecting to vSmart controllers, exchanging fabric policies, and enabling zero-touch, secure SD-WAN deployment.
Summarizes data plane WAN edge router models as physical appliances or virtual edge deployments, with public cloud or NFV options on KVM/ESXi, and two software categories: IOS XE and another.
Describe the virtualised network overlay built on edge routers managed by centralized vsmart controllers. Vault orchestrator authenticates devices and VMANAGE provides centralized management, with on-premises or hostile-environment deployments.
See how Cisco SD-WAN applies a zero trust model with mutual authentication and certificate-based identity, encrypting every packet via SSL/TLS and IPsec across an overlay fabric on any transport.
Cisco SD-WAN employs TLS with two-way SSL to enable mutual authentication between client and server, using public and private keys, RSA signatures, and certificate authorities to secure connections.
Explore how two-way SSL authentication uses digital signatures to secure data by encrypting a message hash with a private key, and verify integrity with a public key and certificate authorities.
Establish the owner's identity and public key with a digital certificate, including the subject, issuer, distinguished name, domain name, serial number, validity dates, and a digital signature.
Generate a public-private key pair, create and sign a certificate signing request, submit it to a certificate authority, and validate the issued certificate with the CA’s public key.
Exchange certificates and validate identities during the mutual handshake with trusted certificate authorities, then negotiate symmetric session keys for encrypted communication.
the control plane is separated from data and management planes and uses TLS connections secured by digital certificates and aes-256, with device authentication and integrity via message digests.
Learn how Cisco sd-wan secures the control plane by establishing and maintaining tls control connections between vSmart controllers, vBond, vManage, and edge routers, with provisional tunnels becoming permanent after authentication.
Explain how intruders attempt control connections across transports, showing how a vBond orchestrator is contacted first, then vSmart and vManage connections with TLS, and how redundancy shapes edge router connections.
Explain the control connections between vSmart, vManage, and vBond components using TLS, detailing full-mesh links among controllers and cluster instances, and edge connections.
Detail mutual authentication of Cisco SD-WAN components using digital certificates within a PKI to establish trusted, secure control connections.
Generate the controller CSR, obtain a signed controller certificate from a certificate authority, and install both the root certificate and the signed certificate on VMANAGE using automated or manual deployment.
Configure Cisco SD-WAN host properties, time settings, user access, and network interfaces in the system settings and network settings, including persistent system IP, V Bond orchestrator, organization name, site ID.
Identify hardware recommendations for the Orchestrator Server, Vedge Cloud Router Server, Vmanage Server, and vSmart Controller server, and configure virtual CPU and memory resources by site count.
Explore on-premises Cisco sd-wan topology with management and transport networks and sd-wan controllers. Learn how ACH and HTTPS enable management access, 1-to-1 NAT, and VSmart, VManage, VBond communication.
Identify and authorize firewall flows to establish tls and ipsec tunnels between sd-wan devices, enabling tls-based control connections among Vmanage, Vsmart, and the bond orchestrator.
Install Cisco SD-WAN controllers on VMware ESX using OVA, establish transport and management networks, and issue certificates to onboard edge devices.
Learn on-prem sd-wan controller deployment on VMware ESXi, configuring VLAN-based management and transport networks, using public or private IPs, and deploying vManage, vBond, and vSmart VMs.
Configure sd-wan controllers via cli or vmanage by setting hostname, system ip, site id, organization name, bond orchestrator address, and enable omp, vpn 512, and vpn 0.
Configure Cisco SD-WAN controllers after booting the virtual machines, secure vmanage by changing the admin password, and set up management VPN 512 and VPN zero tunnel interfaces via ACH.
Explore Cisco sd-wan controller deployment options, including on-premises or private clouds, cloud providers like Azure and AWS, and Cisco hosted cloud as software as a service.
Explore automated certificate signing with Cisco PKI, which greatly simplifies generation of signing requests for each controller, signing by Cisco PKI, and vManage retrieving and installing the certificates.
Configure the organization-name and vBond ip address in vManage settings before creating certificate signing requests, and enable netconf and ssh on the vpn0 tunnel for vBond and vSmart controllers.
CSRs are automatically sent to Cisco PnP cloud service; configure a DNS server to resolve cloudsso.cisco.com and apx.cisco.com, and verify reachability from vManage using vshell and curl on port 443.
Learn how to configure smart account credentials in vManage to file CSR requests and receive certificates, including the signing method, certificate validity period, and the certificate retrieve interval.
Create the controller profile using the Cisco network plug and play portal, log into the portal, and verify the smart and virtual accounts reserved for sd-wan devices.
Add a profile under controller profiles by selecting vbond as controller type, and ensure organization-name matches overlay organization-name, with vbond controller defined as a domain name or ip address.
Engage in a hands-on practice session to define the controller profile. Learn the step-by-step process for configuring the controller profile in Cisco SD-WAN fundamentals.
Generate a CSR for each controller in vManage (Configuration > Certificates > Controllers); Cisco PKI auto signs and installs the certificates, completing without manual intervention.
Review the controllers certificates page to see each certificate expiration date and operation status, noting vBond Updated for vManage and vSmart, and installed for vbond within the SD-WAN virtual account.
Practice session demonstrates how to obtain and install a certificate for vManage within the Cisco SD-WAN Fundamentals course.
Add vBond and vSmart to the overlay network via the vManage GUI, generate signed certificates for authentication, and enter the VPN 0 interface IP and credentials.
Follow along as we add vBond and vSmart controllers and install certificates to secure a Cisco sd-wan deployment.
Learn to check certificate status of sd-wan controllers via the vManage interface, noting green up arrows and the operation status: installed for vBond and updated for vManage and vSmart.
Verify certificate details using commands such as 'show control local-properties' to view basic configuration parameters and local properties of the control plane in Cisco SD-WAN Fundamentals.
Explain how the Cisco SD-WAN underlay provides IP reachability across the transport network using routing protocols, while the overlay forms IPsec tunnels over it to create the SD-WAN fabric.
OMP exchanges route prefixes, cryptokeys, and policy between edge routers and the Vsmart controller for secure overlay routing in Cisco sd-wan. OMP maintains the control plane and handles tloc mappings.
Cisco SD-WAN is a Wide Area Network overlay architecture that applies the principles of Software-Defined Networking into the traditional WAN.
The traditional WAN (wide-area network) function was to connect users at the branch or campus to applications hosted on servers in the data center. WANs are not ready for the unprecedented explosion of WAN traffic that cloud adoption brings. That traffic causes management complexity, application-performance unpredictability, and data vulnerability.
Cisco SD-WAN addresses the current IT challenges. It is designed to meet the needs of modern enterprise applications and the rapidly growing security requirements.
Cisco SDWAN is a solution that allows user to quickly and seamlessly establish an overlay fabric to connect an enterprise’s data centers, branch and campus locations, as well as colocation facilities in order to improve the network’s speed, security, and efficiency.
There are multiple, controller deployment options available for customers. Controllers can be deployed On-premises in the company's data centers on a private cloud built with ESXi or KVM hypervisors or in a public cloud such as AWS or Microdoft Azure.
This course is intended to provide design and deployment guidance to onboard Cisco SD-WAN controllers and covers the process of installing the SD-WAN controller software images on a VMWare ESXI instance and establishing the transport and management networks for the three controllers to communicate.
we will also ensure that each controller has a valid certificate installed.