
Explore the fundamentals and hands-on practice of sd-wan through updated content, migration approaches, and lab access with 18.x and 20.x images, enabling real-world deployment and certification readiness.
What is SD-WAN ?
Software-Defined WAN (SD-WAN) is an overlay architecture that overcomes the biggest drawbacks of traditional
WAN. SD-WAN builds a secure, unified connectivity over any transport (MPLS, Broadband, LTE, VSAT etc.)
and provides simplified operations with centralized management, policy control and application visibility
across the enterprise.
Significance of Viptela
The Most Deployed SD-WAN in Global 1000 Companies .
With SD-WAN built on the Viptela Fabric, enterprises can provide secure connectivity everywhere, deploy
new services and applications faster, and drastically simplify operational complexity in the WAN.
Topics covered :
Curriculum
Section 1:Course Introduction & Why SDWAN
Lecture 1:Viptela Introduction
Lecture 2:WAN Challenges
Lecture 3:New SDWAN Players
Lecture 4:SDN Features Part01
Lecture 5:SDN Features Part02
Lecture 6:Cisco approach to SDN Solution
Lecture 7:Cisco SDWAN Solution Top View
Lecture 8:Viptela Solution Overview
Section 2:Cisco SDWAN Components & Bringup Process
Lecture 9:Solution Elements Control Plan devices
Lecture 10:Solution Elements Data Plan Devices
Lecture 11:11 Lap Topology
Lecture 12:Bringup Sequence Control Plan 01
Lecture 13:Bringup Sequence Control Plan 02
Lecture 14:Bringup Control Plan
Lecture 15:Bring up Data Plan Devices
Lecture 16:Revision about Control & Data Plan Tunnels
Lecture 17:Verification Steps
Section 3:vManage Tour & Device Configuration via Feature & CLI Template
Lecture 18:vManage Tour Part 1
Lecture 19:vManage Tour Part 2
Lecture 20:vManage Dashboard Part03
Lecture 21:Device Configuration via vManage
Lecture 22:What are Device Configuration Template
Lecture 23:Feature Template Creation Part01
Lecture 24:Feature Template Creation Part02
Lecture 25:Apply Feature Template
Lecture 26:CLI Template with Variables
Lecture 27:Template Creation Planning
Section 4:OMP Overlay Management Protocol & TLOC
Lecture 28:what is OMP ? Part 01
Lecture 29:OMP Route Types Part 2
Lecture 30:OMP Routes Verification Part03
Lecture 31:OMP & TLOC Attributes Part04
Lecture 32:OMP Best Path Selection Part05
Lecture 33:OMP Route Redistribution Part06
Section 5:Viptela Smart Policy : Theory
Lecture 34:vSmart Policy Overview part 01
Lecture 35:vSmart Policy Overview part 02 vSmart Policy Architecture Components
Lecture 36:Building blocks to vSmart policy 03
Lecture 37:vSmart Policy Execution & Example 04
Lecture 38:vSmart Policy Processing and Application with Lab 05
Explore why sd-wan overcomes traditional network limits by delivering end-to-end, application-aware transport across multiple links. Learn about security fabric, visibility, per-application routing, and zero-touch provisioning for remote branches.
Explore how traditional networks rely on disjointed VPNs, routers, and WAN optimizers, increasing complexity and cost, while sd-wan unifies fabric with centralized control for cost reductions of 40% to 70%.
Discover how sd-wan decouples data and control planes to centralize intelligence and abstract the network from applications. Learn application-aware routing, logical views, vm mobility, and security integration with ddos protection.
Discover Cisco's approach to software-defined networking with DNA Center and vManage, unifying campus, WAN, and data center automation under a single pane of glass management plane.
Discover Cisco sd-wan's top view: data plane traffic over ipsec tunnels controlled by the vSmart control plane, with vBond and vManage for management and orchestration.
Explore how sd-wan delivers transport-independent connectivity through centralized routing and segmentation, managed by vSmart and vManage. Gain insights into application aware networking, zero-touch provisioning, and secure IPsec fabric.
Learn the sd-wan control plane elements: vmanage, vsmart, vbond, and edge devices, their deployment on esxi or kvm, and core concepts like vpn zero and key propagation.
Examine data plane devices in the sd-wan fabric, including edge and branch routers, licensing implications, and security features such as firewall, DNS filtering, and a built-in TPM chip.
Explore the sd-wan lab topology across two data centers and two branches, including the land and branch ip schemas, viptela fabric connections, and site id based grouping.
Configure the system-wide items for vbond and vsmart deployment—system name, site ID, organization name, vbond location, and vpn zero and vpn 512 settings—and validate and commit while verifying inter-controller reachability.
Bring up the SD-WAN control plane by logging into vmanage, configuring organization and vbond, adding vbond and vsmart controllers, generating CSRs, and installing permanent certificates from a root CA.
Deploy VHA branch devices with minimal configuration, enable automatic dataplane certificate installation via a serial-number list and a one-time password, and validate devices through the we manage dashboard.
Verify the sd-wan fabric by checking control connections, local properties, and certificate install, then validate the data plane with IPsec tunnels, BFD sessions, and inbound/outbound connections.
Explore the Vmanage dashboard front panel, with columns showing device status, transport health, inventory and app health across VSmart, VEdge, and VBond, plus control connections and cloud analytics.
Explore the vmanage dashboard from the control plane to sites, IPsec tunnels, and transport health, analyze latency, jitter, loss, and top applications, and configure application aware routing.
Create, edit, and save non-default and system-wide sd-wan templates, configuring Triple A, banners, logging, BFT, VPN zero, and VPN interface settings.
Learn how to create and attach feature templates in a Viptela SD-WAN environment, customize device templates with variables, and verify configuration with Netconf push and config difference checks.
Build and push a template in Vmanage, then validate deployment. Create variables for host name, site ID, and MPLS IP, then attach to devices with change management.
Discover OMP, the overlay management protocol between vSmart devices, enabling overlay network orchestration, service chaining, traffic engineering, and VPN topology management with control over the underlay.
Understand the three OMP route types—service side VPN routes, TLoc routes, and service routes—and how vSmart uses next-hop attributes to distinguish MPLS and internet paths.
Verify omp routes across cli and gui, examining vpn, tloc, and service routes, and interpret originator, site preference, and chosen, installed, resolved statuses for accurate path selection.
Analyze OMP attributes and TLoc concepts in SD-WAN, including origin, originator, and preference, and demonstrate weight-based load balancing for incoming vs outgoing traffic with color and encapsulation details.
Explore how OMP path selection avoids loops by validating routes, evaluating distance and preferences, and monitoring IPsec tunnels with BFD to update the forwarding table.
Demonstrate redistribution of routes between OSPF and OMP in a branch topology, showing both IGP-to-OMP and OMP-to-OSPF configurations, verification, and origin tracking.
Explore Viptela policy types, including control, data, and app route policies, and learn centralized versus localized policy deployment, traffic lists, and how vManage and vSmart push rules to VEdge devices.
Explore the vsmart policy architecture, comparing control policies (configure and execute on vsmart) with data policies (execute at the Vedge and downloaded from vsmart), and understand policy direction and structure.
Build vSmart control policy to block the 77 prefix from branch one to branch two using a prefix list and VPN ten, outbound; verify branch two does not learn route.
Explore how vSmart policy execution drives app route and control and data policies, including service chaining, traffic engineering, route leaks, flow templates, and nat flow for sd-wan topologies.
Create a hub and spoke sd-wan policy to force traffic through the data center and remove direct branch tunnels. Use vmanage to match tlocs and sites and verify IPsec status.
Master sd-wan policy lab examples from real-life scenarios, including multi topology control policy, service redirection and insertion, data policies, and application aware routing, aligned with Cisco exam prep.
Learn how to implement multi-topology sd-wan policies with hub-and-spoke and full-mesh vpn ten and vpn 20 using Vmanage, including creating control and data policies and applying them.
Learn to implement service insertion in SD-WAN by directing traffic to firewalls and data center hubs, and create and edit hub-and-spoke or full-mesh policies, and test with traceroute.
Configure a data center priority control policy to favor the primary data center, create tloc lists and groups of interest, and apply and verify via centralized policy.
Learn to configure an extranet (root-leak) policy that shares routes from vpn 20 and 40 into vpn 100 and exports back, using a loopback 100 and a centralized control policy.
Explore how app-aware routing uses application ids and sla mappings in centralized data policies to steer traffic across links, with bfd monitoring loss, latency, and jitter.
Configure the app-root policy in Vmanage, define audio/video and web SLA classes, and apply a data policy with MPLS primary and internet backup across all branches and data centers.
verify data policy application aware routing by inspecting policy creation, tunnel status, and channel path for audio video; assess SLA with loss, latency, jitter, and revert to MPLS after testing.
Explore how cloud express enables cloud on ram optimization for SaaS and infra services in the sd-wan fabric, improving latency, jitter, and loss through real-time application visibility.
Discover how to enable viptela analytics in vmanage, fetch app-wise, service-based, and IP-based reports, export them as pdf or excel, and leverage email alerts and custom dashboards.
Learn what iWAN is, the technology behind it, and how DMVPN and performance routing work, then study the migration strategy to SD-WAN.
Understand Iven concepts and how they differ from Cisco SD-Wan, examine your lab setup with the CLI, and learn a step-by-step migration plan from data center to branch.
Provision a dual DC IWAN environment by configuring MPLS and internet paths, setting IP address pools and hub devices in IVAN via Epic M, and integrating NetFlow with live index.
Explore intelligent path control and application aware routing across Ivan and Estevan, featuring ABC visibility, application optimization, cloud security integration, and DMVPN with IPsec and front door.
Explain dynamic multipoint VPN (dmvpn) with IPsec tunnels, on-demand tunneling, hub-and-spoke and spoke-to-spoke topologies, HRP DNS resolution, and phase 3 improvements for scalable, transport-independent Estevan fabric networking.
explore dmvpn hub-and-spoke configurations, create vrfs for mpls and internet transports, and configure gre multipoint tunnels with ipsec profiles for secure vpn connectivity.
Explore performance routing and intelligent path control, from BFR to application aware routing, with a hub master controller pushing policies, SLA-based path decisions, and dynamic monitoring across DMVPN IPsec tunnels.
Migrate from ivan to sd-wan sites with step-by-step guidance for data center, single and dual routers, protocol redistribution, verification, and vsmart to devices policy across 16 videos.
Examine data center migration strategies, comparing before and after topology, with edge devices and redundant links, and describe onboarding to VManage using templates and centralized policy.
Bring up dc edge 1 via bootstrap to onboard the csr device, form the control connection to vmanage, install certificates, and verify onboard progress before pushing the full template.
Configure BGP between core and CSI devices, establish peers, advertise the default route, verify with show commands, and redistribute between BGP and OMP to integrate underlay with the SD-WAN fabric.
Learn to advertise BGP routes into OMP to vsmart, use vsmart as a route reflector, rediscover OMP in BGP with filters; create OMP templates and verify config diff.
Demonstrates redistributing the internal BGP routes from OMP into BGP, using vmanage templates, route policies, and tagging to steer DC1/DC2 DCI traffic in sd-wan.
Configure BGP to redistribute OMP into BGP using vManage, verify routes across vSmart, DCI, and core routers, and apply route policies and tagging to steer reverse traffic.
Migrate branches by upgrading hardware or software images to meet sd-wan requirements, verify router images, set the boot image, reload, then configure bootstrap and push the sd-wan template from vmanage.
Continue branch 3 migration by applying bootstrap config, authenticating, installing the permanent certificate, and confirming the device joins the fabric after template attachment via vmanage.
After migration, validate sd-wan by checking data plane and control plane, certificates, ipsec tunnels, and routing reachability between Estevan and non Estevan sites.
Configure BGP peering between the core router, BCC, and Estevan over MPLS, verify with BGP summary, and redistribute OMP to advertise data-center and MPLS prefixes via sd-wan.
Learn to implement hub-and-spoke central policy in sd-wan by configuring vmanage and vsmart templates, activating the policy, and steering routes via omp from hub to spokes in Estevan data center.
Explore the step-by-step migration from iWAN to Cisco SD-WAN, including deploying Estevan controllers and migrating data centers and branches with attention to features, bandwidth, and deployment models.
Identify sites and prerequisites for migration by comparing feature parity between Ivan and Esteban, bandwidth, and platform capabilities, and document high and low level designs to guide a secure migration.
Explore cloud versus on-prem SD-WAN controller deployment, Cisco hosted controllers with vmanage, vbond, and vsmart, plus migration planning, redundancy, and NetFlow and SNMP integration.
Describe the lab topology with a single DC and three branches, then execute a two-phase migration moving the DC first, then branches via vmanage.
Learn how to use an automation script to back up vmanage to a local directory, clean the vmanage, and perform selective restores of templates, policies, and Vsmart components using regex.
Perform a greenfield data center migration by provisioning minimum fabric-ready configuration on C edge devices, attaching the deployment template in Vmanage, and establishing BGP peering with core routers.
Post migration validation for branch three uses an automation tool to verify control connections, IPsec tunnels, and DC routes, then generate a branch three report for management.
Onboard and migrate branch five from iwan to sdwan by converting BR5BC to sdwan mode, ensuring bootstrap configuration and certificate, then enable controller mode and verify vmanage control connections.
Onboard branch five in SD-WAN, migrate from iwan to SD-WAN, apply and adjust the internet type two template, and validate BGP and IPsec tunnels through vManage troubleshooting.
Learn to use an automation tool to generate comprehensive SD-WAN device reports, pull system and software information across seven devices, and redirect output for review.
Explore Cisco's sd-wan security features, including the firewall, IPS, filtering, and AMP, learned step by step to enhance sd-wan security.
Identify SD-WAN security challenges from external, internal, and cloud-based threats. Learn to secure branch, data center, and cloud edges using Cisco's security stack with DNS, IPS, and URL filtering.
Explore SD-WAN threat defense by examining attack surfaces across branch, data center, and cloud, and implement edge security with IPsec, VPN, firewall, IPS, DNS security, and AMP via Vmanage.
Learn how device identity and security rely on the TPM and Cisco trusted anchor module for secure boot, tamper-proof storage, and automatic certificate validation via PnP and Vmanage.
Explore how the sd-wan fabric secures itself by scalable control and data planes, with vSmart driven routing, OMP, and IPsec tunnels enabling segmented, policy-driven traffic.
Explore how to combine firewall, intrusion prevention, url filtering, dns security, and advanced malware protection into a unified threat management approach, with layer seven inspection and customizable policies.
Learn container architecture with control plane, data plane, and service plane, push config via Vmanage and iac, and explore snort engine workflows, url filtering, amp, and cloud vs on-box lookup.
Download the Cisco virtual image from the SD-WAN XC router and ISR platform, upload it to the Vmanage maintenance software repository, and configure security policies for branch devices.
Navigate the Cisco SD-WAN 19.1 security dashboard, featuring firewall, IPS, and AMP insights, and explore device-level monitoring, time filters, and embedded security tools across main, VPN, and maintenance views.
Learn to implement firewall and intrusion prevention policies in the Cisco SD-WAN vmanage dashboard. Explore app aware firewall, zone based rules, and route leakage across VPNs with gui and cli.
Configure SD-WAN guest access security by implementing app aware firewall and URL filtering, managing whitelists and blacklists, and integrating DNS security with Cisco Umbrella for threat protection.
Explore Python programming for SD-WAN automation, with a focus on integrating Python with the SD-WAN API, building a foundation through a comprehensive Python video series.
Explore integer, floating-point, and boolean data types in Python, with binary and hexadecimal representations, and verify types using type(). Note Python is case sensitive.
Learn how strings work with quotes, escaping, and printing, and how to use lists as simple data structures, with examples in Python 3.
Learn how to declare and use variables in Python, build expressions with operators, understand precedence, and add comments. Explore identifiers, literals, and printing, including text and number concatenation.
Explore user defined functions in Python, pass arguments with defaults, use the asterisk and double asterisk for variable length inputs, and compute area of circle with input and pi.
Learn to define and call functions, use input and print statements, and apply if logic to find the biggest among numbers and determine pass or fail through practice exercises.
Explore while and for loops, learn loop conditions and nesting, and practice iterating over lists, tuples, and dictionaries to perform actions like squaring numbers.
Learn Python loop control with break, continue, and pass, explore how break exits a loop when a space matches, how continue skips iterations, and how pass acts as a placeholder.
Explore recursion through a factorial example, master string slicing and immutability in Python, and leverage built-in string functions like split, replace, count, and startswith for practical programming.
Explore Python string modules and arrays, importing string to access ascii letters, lowercase, uppercase digits, and using formatter and template, plus array indexing and type codes B and I.
Master Python list operations and tuples, exploring mutability and common methods such as append, extend, insert, pop, remove, reverse, and sort, plus for loops and API usage.
Explore how lists behave with aliasing and cloning, showing how mutations affect copies and how to preserve originals. Compare list operations, list comprehensions, and lambdas with tuples as immutable sequences.
Master dictionaries as unordered key-value data structures, using methods like keys, get, items, update, and delete, practice iterating key-value pairs and lists of dictionaries to print user ids and names.
Learn to perform file operations in Python, including reading hostnames from storage, writing and appending to text files, and distinguishing text and binary modes while opening and closing files.
Explore common programming errors and exceptions, and learn to handle them with try and except blocks to gracefully manage division by zero and other runtime issues.
Explore how to import built-in and custom modules, call functions across programs, and reuse code by packaging and exporting modules, including examples with date, time, and calendar.
What is SD-WAN ?
Software-Defined WAN (SD-WAN) is an overlay architecture that overcomes the biggest drawbacks of traditional
WAN. SD-WAN builds a secure, unified connectivity over any transport (MPLS, Broadband, LTE, VSAT etc.)
and provides simplified operations with centralized management, policy control and application visibility
across the enterprise.
Significance of Viptela
The Most Deployed SD-WAN in Global 1000 Companies .
With SD-WAN built on the Viptela Fabric, enterprises can provide secure connectivity everywhere, deploy
new services and applications faster, and drastically simplify operational complexity in the WAN.
Topics covered :
Section 1:Introduction & bringup process
Lecture 1:Introduction & Bring up Process of Viptela Controllers
Lecture 2:Viptela Solution Overview
Lecture 3:Viptela Bringup Process installation of vEdge
Lecture 4:firewall Ports & Server hardware requirements
Lecture 5:Bring up the control connection and check the Certificate
Lecture 6:Bring up the vEdge to vEdge IPSec Tunnel
Section 2:Device Configuration & Linux Skills
Lecture 7:Configuration Elements in a Device
Lecture 8:Lab Time Trouble ticket
Lecture 9:SDWAN Linux Skills
Section 3:vManage Tour & Feature Template
Lecture 10:vManage Tour Part 1
Lecture 11:vManage Tour Part 2
Lecture 12:Feature Template Part 1
(Preview enabled)
Lecture 13:Feature Template Part 2
Section 4:OMP Overlay Management Protocol & TLOC
Lecture 14:OMP Overlay Managment Route Part 1
Lecture 15:OMP Overlay Managment Route Part 2
Lecture 16:Transport Locator TLOC
Section 5:Viptela Smart Policy : Theory
Lecture 17:vSmart Policy Overview part 01
Lecture 18:vSmart Policy Overview part 02 vSmart Policy Architecture Components
Lecture 19:Building blocks to vSmart policy 03
Lecture 20:vSmart Policy Execution & Example 04
Lecture 21:vSmart Policy Processing and Application 05
Section 5:Viptela Smart Policy
Lecture 22:Viptela Policy Part 1
Lecture 23:Viptela Policy Part 2
Section 7:Troubleshooting & Wrap up
Lecture 24:Viptela Troubleshooting
Lecture 25:Lab