Cisco SDWAN Questions Flashcards

1
Q

What is the Cisco SD-WAN solution?

A

Software-defined wide area network is the separation of the control plane and forwarding planes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the key benefits offered by Cisco SD-WAN?

A

Transport independent.
Secure Connectivity: IPSEC & (TLS/DTLS)
The separation of the control and forwarding planes.
LAN Segmentation.
Onboard to cloud Apps.
Cloud Connectivity.
WAN Analytics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are vSmart controllers?

A

The vSmart is the Control plane of SDWAN. Pushes global policies via OMP (TLS/DTLS) to the edge routers. It can be deployed on-prem, cloud, or Cisco-cloud hosted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are vBond orchestrators?

A

The vBond is the Orchestration Plane of SDWAN. First point of authentication (white-list model) for the edge routers. Distributes the list of vSmarts/ vManage to all vEdge routers after authorization is done. Maintains a Complete chassis number & S/N Token database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Cisco vManage?

A

The Cisco vManage manages the entire solution. You can log in on the Cisco vManage dashboard to manage and centrally control the WAN. Configures routers via Local policies using NETCONF. You can create and push templates from vManage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the elements of Viptela SD-WAN?

A

vManage: The Network management (GUI) plane. A central dashboard for management and configuration.

vSmart: The Control plane. pushes global policies via OMP (TLS/DTLS) to the edge routers.

vBond: The Orchestration Plane. First point of authentication (white-list model). Distributes the list of vSmarts/ vManage to all vEdge routers.

vEdge/cEdge: The WAN edge routers. Establishes secure control plane with vSmart controllers (OMP).

OMP: Overlay routing enables the distribution of routing information across all sites within a VPN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is site-id?

A

Is a Unique per-site number assigned to identify branches and is used in the policy application. Needed for a bootstrap configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Virtual Private Network (VPN) within SDWAN?

A

In the SD-WAN overlay, Virtual Private Networks (VPNs) provide segmentation, just like Virtual Routing and Forwarding instances (VRFs) . Each VPN is distinct from the others and has its forwarding table.

  • VPN 0: This is the transport VPN. It has interfaces to connect to WAN transports. Secure DTLS/TLS connections to vSmart between vSmart or vBond.
  • VPN 512: It is the management VPN. It is responsible for carrying the out-of-band management traffic to and from the Cisco SD-WAN devices.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the specifications to be met for ZTP?

A
  1. The transport VPN interface is configured by default as DHCP for ZTP.
  2. In vManage, it is necessary to have an appropriate device configuration template for the vEdge router.
  3. The system IP address & site ID must be configured on the edge router.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Familiarity and hands-on experience with Cisco (Viptela) SD-WAN?

A
  1. Created a home lab with ESXi and vEdge images and CSR1000v to practice SDWAN.
  2. Designed and roll-out SDWAN to a trucking company with 130 locations in the US and Mexico.
  3. Rolled out SDWAN at a financial institution with 160 branches in the US.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the Cisco SD-WAN controllers?

A

vManage, vSmart and vBond.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is your experience with deploying the SD-WAN controllers?

A

Deployed on-prem and on the AWS cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Name the main (overlay) protocol used in Cisco SD-WAN?

A

OMP/Overlay Management Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are VPN 0 and VPN 512 used for?

A
  • VPN 0: This is the transport VPN. It has interfaces to connect to WAN transports. Secure DTLS/TLS connections to vSmart between vSmart or vBond.
  • VPN 512: It is the management VPN. It is responsible for carrying the out-of-band management traffic to and from the Cisco SD-WAN devices.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the default overlay topology type without any configuration?

A

Full-mesh

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A TLOC (Transport Locator) consists of a tuple of three values?

A

System IP, Transport Color, and Encapsulation type

17
Q

What protocol is used to determine loss, latency, and jitter for app-aware routing?

A

BFD (Bidirectional Forwarding Detection)

18
Q

How is SDWAN different from a traditional WAN?

A

The Traditional WAN has the following:
Management plane: Located in the router
Control plane: Located in the router
Data plan: Located in the router

19
Q

What is SYSTEM-IP?

A

Unique identifier per device. & Router-id for BGP, OSPF, EIGRP. Needed for a bootstrap configuration.

20
Q

Why SDWAN uses color in its configuration?

A

Each tunnel interface is assigned a unique color for identifation.

21
Q

Edge router bootstrap configuration?

A
  1. WAN connectivity w/DNS
  2. System-IP
  3. Site-ID
  4. org-name
  5. vBond IP or DNS
    - Device must be whitelisted with vBond
    vpn0: WAN Interface
    vpn512: Loopback (management) Interface
22
Q

vBond bootstrap configuration?

A
  1. WAN connectivity w/DNS
  2. System-IP
  3. Site-ID
  4. org-name
  5. vBond IP or DNS (Self-configuration)
    vpn0: WAN Interaface
    vpn512: Loopback (management) Interface
23
Q

vSmart bootstrap configuration?

A
  1. WAN connectivity w/DNS
  2. System-IP
  3. Site-ID
  4. org-name
  5. vBond IP or DNS
    vpn0: WAN Interaface
    vpn512: Loopback (management) Interface
24
Q

vManage bootstrap configuration?

A
  1. WAN connectivity w/DNS
  2. System-IP
  3. Site-ID
  4. org-name
  5. vBond IP or DNS
    vpn0: WAN Interaface
    vpn512: Loopback (management) Interface
25
Q

What is NBAR used in SDWAN?

A

Application visibility for Deep Packet Inspection (DPI).

26
Q

Types of Routes in SDWAN?

A
  1. OMP Routes (vRoutes): Prefixes learned from site-local
  2. TLOCs: Ties OMP route to a physical Interface.
  3. Service Routes: Ties OMP route to an advertised network service.