
What is SD-WAN ?
Software-Defined WAN (SD-WAN) is an overlay architecture that overcomes the biggest drawbacks of traditional
WAN. SD-WAN builds a secure, unified connectivity over any transport (MPLS, Broadband, LTE, VSAT etc.)
and provides simplified operations with centralized management, policy control and application visibility
across the enterprise.
Significance of Viptela
The Most Deployed SD-WAN in Global 1000 Companies .
With SD-WAN built on the Viptela Fabric, enterprises can provide secure connectivity everywhere, deploy
new services and applications faster, and drastically simplify operational complexity in the WAN.
Topics covered :
Curriculum
Section 1:Course Introduction & Why SDWAN
Lecture 1:Viptela Introduction
Lecture 2:WAN Challenges
Lecture 3:New SDWAN Players
Lecture 4:SDN Features Part01
Lecture 5:SDN Features Part02
Lecture 6:Cisco approach to SDN Solution
Lecture 7:Cisco SDWAN Solution Top View
Lecture 8:Viptela Solution Overview
Section 2:Cisco SDWAN Components & Bringup Process
Lecture 9:Solution Elements Control Plan devices
Lecture 10:Solution Elements Data Plan Devices
Lecture 11:11 Lap Topology
Lecture 12:Bringup Sequence Control Plan 01
Lecture 13:Bringup Sequence Control Plan 02
Lecture 14:Bringup Control Plan
Lecture 15:Bring up Data Plan Devices
Lecture 16:Revision about Control & Data Plan Tunnels
Lecture 17:Verification Steps
Section 3:vManage Tour & Device Configuration via Feature & CLI Template
Lecture 18:vManage Tour Part 1
Lecture 19:vManage Tour Part 2
Lecture 20:vManage Dashboard Part03
Lecture 21:Device Configuration via vManage
Lecture 22:What are Device Configuration Template
Lecture 23:Feature Template Creation Part01
Lecture 24:Feature Template Creation Part02
Lecture 25:Apply Feature Template
Lecture 26:CLI Template with Variables
Lecture 27:Template Creation Planning
Section 4:OMP Overlay Management Protocol & TLOC
Lecture 28:what is OMP ? Part 01
Lecture 29:OMP Route Types Part 2
Lecture 30:OMP Routes Verification Part03
Lecture 31:OMP & TLOC Attributes Part04
Lecture 32:OMP Best Path Selection Part05
Lecture 33:OMP Route Redistribution Part06
Section 5:Viptela Smart Policy : Theory
Lecture 34:vSmart Policy Overview part 01
Lecture 35:vSmart Policy Overview part 02 vSmart Policy Architecture Components
Lecture 36:Building blocks to vSmart policy 03
Lecture 37:vSmart Policy Execution & Example 04
Lecture 38:vSmart Policy Processing and Application with Lab 05
Discover how sd-wan decouples data and control planes to centralize intelligence and abstract the network from applications. Learn application-aware routing, logical views, vm mobility, and security integration with ddos protection.
Discover Cisco's approach to software-defined networking with DNA Center and vManage, unifying campus, WAN, and data center automation under a single pane of glass management plane.
Discover Cisco sd-wan's top view: data plane traffic over ipsec tunnels controlled by the vSmart control plane, with vBond and vManage for management and orchestration.
Explore how sd-wan delivers transport-independent connectivity through centralized routing and segmentation, managed by vSmart and vManage. Gain insights into application aware networking, zero-touch provisioning, and secure IPsec fabric.
Examine data plane devices in the sd-wan fabric, including edge and branch routers, licensing implications, and security features such as firewall, DNS filtering, and a built-in TPM chip.
Explore the sd-wan lab topology across two data centers and two branches, including the land and branch ip schemas, viptela fabric connections, and site id based grouping.
Configure the system-wide items for vbond and vsmart deployment—system name, site ID, organization name, vbond location, and vpn zero and vpn 512 settings—and validate and commit while verifying inter-controller reachability.
Bring up the SD-WAN control plane by logging into vmanage, configuring organization and vbond, adding vbond and vsmart controllers, generating CSRs, and installing permanent certificates from a root CA.
Deploy VHA branch devices with minimal configuration, enable automatic dataplane certificate installation via a serial-number list and a one-time password, and validate devices through the we manage dashboard.
Verify the sd-wan fabric by checking control connections, local properties, and certificate install, then validate the data plane with IPsec tunnels, BFD sessions, and inbound/outbound connections.
Explore the vmanage dashboard from the control plane to sites, IPsec tunnels, and transport health, analyze latency, jitter, loss, and top applications, and configure application aware routing.
Build and push a template in Vmanage, then validate deployment. Create variables for host name, site ID, and MPLS IP, then attach to devices with change management.
Analyze OMP attributes and TLoc concepts in SD-WAN, including origin, originator, and preference, and demonstrate weight-based load balancing for incoming vs outgoing traffic with color and encapsulation details.
Explore Viptela policy types, including control, data, and app route policies, and learn centralized versus localized policy deployment, traffic lists, and how vManage and vSmart push rules to VEdge devices.
Create a hub and spoke sd-wan policy to force traffic through the data center and remove direct branch tunnels. Use vmanage to match tlocs and sites and verify IPsec status.
Master sd-wan policy lab examples from real-life scenarios, including multi topology control policy, service redirection and insertion, data policies, and application aware routing, aligned with Cisco exam prep.
Learn to implement service insertion in SD-WAN by directing traffic to firewalls and data center hubs, and create and edit hub-and-spoke or full-mesh policies, and test with traceroute.
Configure a data center priority control policy to favor the primary data center, create tloc lists and groups of interest, and apply and verify via centralized policy.
verify data policy application aware routing by inspecting policy creation, tunnel status, and channel path for audio video; assess SLA with loss, latency, jitter, and revert to MPLS after testing.
Discover how to enable viptela analytics in vmanage, fetch app-wise, service-based, and IP-based reports, export them as pdf or excel, and leverage email alerts and custom dashboards.
Learn what iWAN is, the technology behind it, and how DMVPN and performance routing work, then study the migration strategy to SD-WAN.
Provision a dual DC IWAN environment by configuring MPLS and internet paths, setting IP address pools and hub devices in IVAN via Epic M, and integrating NetFlow with live index.
Explore intelligent path control and application aware routing across Ivan and Estevan, featuring ABC visibility, application optimization, cloud security integration, and DMVPN with IPsec and front door.
Explain dynamic multipoint VPN (dmvpn) with IPsec tunnels, on-demand tunneling, hub-and-spoke and spoke-to-spoke topologies, HRP DNS resolution, and phase 3 improvements for scalable, transport-independent Estevan fabric networking.
explore dmvpn hub-and-spoke configurations, create vrfs for mpls and internet transports, and configure gre multipoint tunnels with ipsec profiles for secure vpn connectivity.
Explore performance routing and intelligent path control, from BFR to application aware routing, with a hub master controller pushing policies, SLA-based path decisions, and dynamic monitoring across DMVPN IPsec tunnels.
Migrate from ivan to sd-wan sites with step-by-step guidance for data center, single and dual routers, protocol redistribution, verification, and vsmart to devices policy across 16 videos.
Demonstrates redistributing the internal BGP routes from OMP into BGP, using vmanage templates, route policies, and tagging to steer DC1/DC2 DCI traffic in sd-wan.
Configure BGP to redistribute OMP into BGP using vManage, verify routes across vSmart, DCI, and core routers, and apply route policies and tagging to steer reverse traffic.
Migrate branches by upgrading hardware or software images to meet sd-wan requirements, verify router images, set the boot image, reload, then configure bootstrap and push the sd-wan template from vmanage.
Continue branch 3 migration by applying bootstrap config, authenticating, installing the permanent certificate, and confirming the device joins the fabric after template attachment via vmanage.
After migration, validate sd-wan by checking data plane and control plane, certificates, ipsec tunnels, and routing reachability between Estevan and non Estevan sites.
Configure BGP peering between the core router, BCC, and Estevan over MPLS, verify with BGP summary, and redistribute OMP to advertise data-center and MPLS prefixes via sd-wan.
Identify sites and prerequisites for migration by comparing feature parity between Ivan and Esteban, bandwidth, and platform capabilities, and document high and low level designs to guide a secure migration.
Describe the lab topology with a single DC and three branches, then execute a two-phase migration moving the DC first, then branches via vmanage.
Learn how to use an automation script to back up vmanage to a local directory, clean the vmanage, and perform selective restores of templates, policies, and Vsmart components using regex.
Explore Cisco's sd-wan security features, including the firewall, IPS, filtering, and AMP, learned step by step to enhance sd-wan security.
Explore SD-WAN threat defense by examining attack surfaces across branch, data center, and cloud, and implement edge security with IPsec, VPN, firewall, IPS, DNS security, and AMP via Vmanage.
Learn how device identity and security rely on the TPM and Cisco trusted anchor module for secure boot, tamper-proof storage, and automatic certificate validation via PnP and Vmanage.
Explore how the sd-wan fabric secures itself by scalable control and data planes, with vSmart driven routing, OMP, and IPsec tunnels enabling segmented, policy-driven traffic.
Download the Cisco virtual image from the SD-WAN XC router and ISR platform, upload it to the Vmanage maintenance software repository, and configure security policies for branch devices.
Navigate the Cisco SD-WAN 19.1 security dashboard, featuring firewall, IPS, and AMP insights, and explore device-level monitoring, time filters, and embedded security tools across main, VPN, and maintenance views.
Learn to implement firewall and intrusion prevention policies in the Cisco SD-WAN vmanage dashboard. Explore app aware firewall, zone based rules, and route leakage across VPNs with gui and cli.
Explore integer, floating-point, and boolean data types in Python, with binary and hexadecimal representations, and verify types using type(). Note Python is case sensitive.
Explore user defined functions in Python, pass arguments with defaults, use the asterisk and double asterisk for variable length inputs, and compute area of circle with input and pi.
Explore recursion through a factorial example, master string slicing and immutability in Python, and leverage built-in string functions like split, replace, count, and startswith for practical programming.
Master Python list operations and tuples, exploring mutability and common methods such as append, extend, insert, pop, remove, reverse, and sort, plus for loops and API usage.
Explore how lists behave with aliasing and cloning, showing how mutations affect copies and how to preserve originals. Compare list operations, list comprehensions, and lambdas with tuples as immutable sequences.
Master dictionaries as unordered key-value data structures, using methods like keys, get, items, update, and delete, practice iterating key-value pairs and lists of dictionaries to print user ids and names.
Explore common programming errors and exceptions, and learn to handle them with try and except blocks to gracefully manage division by zero and other runtime issues.
What is SD-WAN ?
Software-Defined WAN (SD-WAN) is an overlay architecture that overcomes the biggest drawbacks of traditional
WAN. SD-WAN builds a secure, unified connectivity over any transport (MPLS, Broadband, LTE, VSAT etc.)
and provides simplified operations with centralized management, policy control and application visibility
across the enterprise.
Significance of Viptela
The Most Deployed SD-WAN in Global 1000 Companies .
With SD-WAN built on the Viptela Fabric, enterprises can provide secure connectivity everywhere, deploy
new services and applications faster, and drastically simplify operational complexity in the WAN.
Topics covered :
Section 1:Introduction & bringup process
Lecture 1:Introduction & Bring up Process of Viptela Controllers
Lecture 2:Viptela Solution Overview
Lecture 3:Viptela Bringup Process installation of vEdge
Lecture 4:firewall Ports & Server hardware requirements
Lecture 5:Bring up the control connection and check the Certificate
Lecture 6:Bring up the vEdge to vEdge IPSec Tunnel
Section 2:Device Configuration & Linux Skills
Lecture 7:Configuration Elements in a Device
Lecture 8:Lab Time Trouble ticket
Lecture 9:SDWAN Linux Skills
Section 3:vManage Tour & Feature Template
Lecture 10:vManage Tour Part 1
Lecture 11:vManage Tour Part 2
Lecture 12:Feature Template Part 1
(Preview enabled)
Lecture 13:Feature Template Part 2
Section 4:OMP Overlay Management Protocol & TLOC
Lecture 14:OMP Overlay Managment Route Part 1
Lecture 15:OMP Overlay Managment Route Part 2
Lecture 16:Transport Locator TLOC
Section 5:Viptela Smart Policy : Theory
Lecture 17:vSmart Policy Overview part 01
Lecture 18:vSmart Policy Overview part 02 vSmart Policy Architecture Components
Lecture 19:Building blocks to vSmart policy 03
Lecture 20:vSmart Policy Execution & Example 04
Lecture 21:vSmart Policy Processing and Application 05
Section 5:Viptela Smart Policy
Lecture 22:Viptela Policy Part 1
Lecture 23:Viptela Policy Part 2
Section 7:Troubleshooting & Wrap up
Lecture 24:Viptela Troubleshooting
Lecture 25:Lab