
Section 1:
Introduction
Lecture 1:
Introduction of the Course
Section 2:
Cisco SD-WAN Overlay Network
Lecture 2:
Examining Cisco SD-WAN Architecture
Lecture 3:
Examining the Cisco SD-WAN Architecture – OMP
Section 3:
Cisco SD-WAN Deployment
Lecture 4:
Examining Cisco SD-WAN Deployment Options
Lecture 5:
Examining Cisco SD-WAN Deployment On-Premises
Lecture 6:
Examining Cisco SD-WAN Deployment Using Enterprise CA
Lecture 7:
Examining Cisco SD-WAN Controller Placement and Challenges
Lecture 8:
Deploying the vEdge Devices
Lecture 9:
Deploying the cEdge Devices
Lecture 10:
Deploying Edge Devices – Working with NAT
Lecture 11:
Deploying Edge Devices with Zero-Touch Provisioning – Part 1
Lecture 12:
Deploying Edge Devices with Zero-Touch Provisioning – Part 2
Lecture 13:
Device Configuration Templates – Part-1
Lecture 14:
Device Configuration Templates – Part-2
Lecture 15:
Redundancy, High Availability, and Scalability
Section 4:
Cisco SD-WAN Routing Options
Lecture 16:
Cisco SD-WAN Routing Options - Overview
Lecture 17:
Using Dynamic Routing – Part 1
Lecture 18:
Using Dynamic Routing – Part 1
Lecture 19:
Providing Site Redundancy & High Availability
Lecture 20:
Configuring Transport-Side Connectivity
Lecture 21:
Bidirectional Forwarding Detection (BFD)
Lecture 22:
Implementing TLOC Extensions – Path Redundancy
Section 5:
Cisco SD-WAN Policy Configuration
Lecture 23:
Cisco SD-WAN Policy Overview
Lecture 24:
Defining Advanced Control Policies – Part 1
Lecture 25:
Defining Advanced Control Policies – Part 2
Lecture 26:
Defining Advanced Data Policies – Traffic Engineering
Lecture 27:
Defining Advanced Data Policies – Application Firewalls
Lecture 28:
Defining Advanced Data Policies – Zone-Based Firewalls
Lecture 29:
Implementing AAR (Application-Aware Routing)
Examine the Cisco SD-WAN architecture and its decoupled data and control planes. Learn how edge routers, vsmart controllers, vbond, and vmanage enable secure, zero-touch IPsec tunnels and policy-driven routing.
Explore how OMP carries control plane info between routers and vSmart controllers in a Cisco SD-WAN fabric, enabling redundant, full-mesh peering and NAT traversal with vbond.
Examine Cisco sd-wan deployment options across cloud and on-premises, including Cisco Cloud, AWS and Azure, with controller onboarding, Vbond and Vmanage, redundancy across VPCs, and multi-tenant versus dedicated models.
Explore on-premises Cisco sd-wan deployment using virtual controllers vmanage, vbond, and vsmart with separate management and transport vpns, and perform minimal initial configuration: system id, site, organization, and certificates.
Deploy Cisco sd-wan using enterprise CA by generating a CSR, signing it, installing the certificate on Vmanage, and enabling VPN zero with IPsec.
Examine Cisco sd-wan controller placement and challenges, from cloud versus on-prem deployment to dmz setup, ensuring public IP reachability, dual transport redundancy, nat traversal, and required firewall ports for ipsec.
Deploy and validate vEdge devices by uploading the vanish devices list to Vmanage, activating cloud instances, configuring VPNs and interfaces, and verifying device status and controller connections.
Explain NAT and port hopping for edge devices behind NAT in Cisco SD-WAN, detailing full cone, restricted cone, port-restricted, and symmetric NAT, and how IPsec tunnels form.
Deploy Cisco SD-WAN edge devices with zero-touch provisioning by binding orders to a smart account, authenticating via vbond, and pushing full config from Vmanage through the plug-and-play flow.
Explore creating and deploying device configuration templates in Cisco SD-WAN, upload and validate CSV variables, preview CLI configurations, and push changes to multiple devices via Vmanage mode with optional parameters.
Explore redundancy, high availability, and scalability in Cisco sd-wan across vbond, vmanage, and vsmart controllers. Learn how clustering, regional affinity, and FCN load balancing ensure continuous data plane operation.
Explore sd-wan routing options across the fabric, including omp redistribution, amp, service and transport side protocols, site redundancy with l3 and layer-2 options, and transport-side configuration and lock options.
Explore dynamic routing in Cisco sd-wan, focusing on configuring bgp on the service and transport sides, redistributing with omp, and implementing loop-avoidance using path numbers and site IDs.
Configure transport-side connectivity for Cisco SD-WAN by enabling BGP or OSPF on VPN zero, using templates or CLI, and setting up loopback and physical interfaces with prefix lists and redistribution.
Explore bidirectional forwarding detection (bfd) in sd-wan to monitor link health. Configure bfd via Vmanage feature templates to reroute traffic and down ipsec tunnels on path failure.
Implement TLOC extensions to achieve site-wide path redundancy by extending MPLS and internet connectivity between two routers, forming dual data and control plane tunnels across all transports.
Define advanced control policies for a Cisco SD-WAN fabric using vmanage and vsmart, covering inbound and outbound routing, policy definitions, service chaining, traffic engineering, and arbitrary VPN topology.
Define advanced Cisco SD-WAN control policies to shape inter-region traffic among hub-and-spoke sites, using match and actions to steer routes and enable service chaining with firewalls across VPNs.
Learn to define advanced data policies for traffic engineering in Cisco SD-WAN using vManage, with centralized and localized policies, service chaining, and MPLS versus internet transport.
Define advanced data policies with application firewalls to block FTP traffic between branch sites in VPN two, using groups of interest, VPN lists, and application lists, then apply the policy.
Discover how direct internet access (DIA) and NAT in Cisco SD-WAN offload internet traffic from the WAN, reducing latency and costs while boosting branch user experience.
Explore advanced data policies for QoS in Cisco SD-WAN, including centralized vs localized policies, classification into forwarding classes, and queuing, scheduling, policers, and rewrites.
Explore Cisco sd-wan hybrid deployment strategies, assessing circuits at branches and data centers, designing active redundancy, and enabling direct internet access for improved cloud and SaaS traffic.
Learn to perform a brownfield sd-wan migration that retains the router to preserve unified communications, using layer two redundancy, and overlay traffic via mpls or internet with ospf/bgp redistribution.
Master day-two operations for Cisco SD-WAN by using rest APIs to manage the fabric, provision devices, and monitor performance. Dive into alarms, events, audit logs, and centralized notifications for troubleshooting.
Explore day-2 data operations in sd-wan: access local and remote logs, use tcpdump for packet capture, download pcap files, and automate with rest APIs and Python scripts.
Upgrade the sd-wan fabric in a staged sequence: upgrade vmanage first, then vbond and vsmart in groups, tag devices, test at sites, wait 24 hours, then upgrade the rest.
Learn to build your own Cisco SD-WAN Viptela lab by deploying vmanage, vsmart, vbond, CSR 1000V routers on VMware, establishing the overlay and configuring centralized policies.
Explore the Vmanage dashboard and its components, including vsmart controllers, vbond, and Vonage devices, to monitor real-time device status, control sessions, and application aware routing insights.
Explore the Vmanage monitoring features for geography, network, alarms, events, and logs, and learn how to monitor Vmanage, vsmart, vbond, and wan edge devices.
Explore vManage monitoring features, including alarms, events, and audit logs, to diagnose outages, correlate issues, and track configuration changes with detailed device and task history.
Explore vmanage tools to access all devices from a single place. Use the ssh terminal, rediscover network, and perform operational commands for troubleshooting.
Configure OMP for vsmart controllers using a vmanage feature template, adjusting path limits, timers, and backup routes, with vsmart acting as a route reflector and manager of the control plane.
Verify and troubleshoot OMP configurations on vsmart controllers and edge devices using CLI and vManage, reviewing peering, routes, and logs, including VPN and IPsec details.
Verify OMP in Vmanage by accessing monitor network, selecting a vsmart controller, and using real time CLI to view OMP peers, site IDs, routes advertised and received, and related logs.
Configure a vpn in the sd-wan fabric using Cisco vManage feature templates and device templates, including vpn numbers, dns, host mappings, routes, and per-vpn advertising and service routes.
Configure VRRP on two sd-wan routers via vmanage using the interface feature template, set group ID 10 and a virtual IP, push, and verify master and backup roles.
Configure BGP in sd-wan via Vmanage by creating a BGP feature template, selecting a device model, and applying it through a device template, including neighbors and OMP redistribution.
Learn zero-touch provisioning of a vEdge router in a Cisco SD-WAN lab onboarding via GDB and Vmanage, using edge lists and device templates, and verify control and data planes.
Configure and push additional features to sd-wan devices using device templates and feature templates, such as enabling OSPF on the landside, verifying neighbors, and removing configurations when needed.
Verify OSPF using the CLI and VManage, checking a full-state neighbor, router IDs, and the VPN ten interface; review intra-area routes and LSA data in the OSPF database.
Remove specific configurations from a device using the device template in Vmanage, exemplified by removing OSPF from VPN ten and validating the config diff and push.
Configure a multi-topology control policy with route filtering to make VPN ten hub-and-spoke and VPN 20 full mesh, using Vmanage and Vsmart.
Configure a multi-topology control policy to route vpn ten hub-and-spoke via the data center, while vpn 20 remains full mesh using tloc changes on the vsmart controller.
Configure a control policy to insert a firewall service, routing inter-branch traffic through the sd-wan fabric data center firewall. Deploy via vSmart and verify firewall-based routing between branches.
The Implementing Cisco SD-WAN Solutions (SDWAN300) v1.0 course gives you deep-dive training about how to design, deploy, configure, and manage your Cisco® Software-Defined WAN (SD-WAN) solution in a large-scale live network, including how to migrate from legacy WAN to SD-WAN. You will learn best practices for configuring routing protocols in the data center and the branch, as well as how to implement advanced control, data, and application-aware policies. The course also covers SD-WAN deployment and migration options, placement of controllers, how to deploy and replace edge devices, and how to configure Direct Internet Access (DIA) breakout.
This course helps you prepare to take the Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) exam, which is part of the new CCNP Enterprise certification and the Cisco Certified Specialist - Enterprise SD-WAN Implementation certification. The exam is available form February 24, 2020.