ENCOR Flashcards

1
Q

SD WAN - what is the controller

A

vManage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

vManage is what type of itnerface

A

HTTP website

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

vSmart

A

Control plane

Pushes policies down to edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

vEdge

A

Edge Router in SD_WAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

vBond

A

Orchestrator - Zero-touch provisioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Newer cisco verison of vEdge

A

cEdge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SD-WAN - what topologoes is enabled with the most basic liences?

A

Hop and spoke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SDWAN topologies

A

Hub and Spoke
Partial Mesh
Full mesh
PTP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In SD-WAN - What technologies enable application aware SLA(service-levelagreement)?

A

DPI

6-Tuple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DPI stands for

A

Deep Packet Inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

6-Tuple refers too

A

6 Tuple is inspection of :

  • S,D IP
  • S,D Port
  • QoS -DSCP
  • IP protocol
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SD-WAN enables a user to deal with multiple WAN links, such as a leased line and MPLS circuit. What are the different SD-WAN configurations avaliable?

A

Active-Active
Active-Active (weighted)
Active-Standby (pinning)
Application-Aware SLA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SD-WAN : multiple WAN’s - Active-Active

A

Load balance across multiple WAN connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SD-WAN : multiple WAN’s - Active-Active (weighted)

A

Weighted Load balance across multiple WAN connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SD-WAN : multiple WAN’s - Active-Standby (pinning)

A

some applications always use one link, others (such as voice) always use one link

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SD-WAN : multiple WAN’s - Application-Aware SLA

A

Tracking metrics and responding

17
Q

SD-WAN - Protocol between vSmart and vEdge

A

OMP - Overlay Management Protocol

18
Q

OMP is responsible for telling …

A

telling vEdge/cEdge on how to create IPsec tunnels

19
Q

OMP uses what protocols

A

TCP/TLS

20
Q

bVond - Important considerations

A

Must have a public IP address

1:1 NAT

21
Q

Why is NAT traversal required in SD-WAN

A

IPsec tunnels are L3 so there is NO port numbers for the NAT to grab onto

22
Q

If NAT-T is enabled, what does SD-WAN do when it detects NAT is enabled

A

Switches from IPsec headers to UDP 4500

Allows NAT traversal

23
Q

What does vBond push new devices to vManage

A

Admins must approve new devices to ecosystem

Gets pushed to vSmart

24
Q

Why is vBond needed?

A

vSmart and vEdge don’t know about each other

25
Q

How does vBond help with NAT travesal?

A

Both vEdge/cEdge on a side of a NAT firewall
vBond sends packets at same time (knows public/private addresses) to each device which builds that NAT mappings

OR vBond sends dummy packets

26
Q

SD-WAN Controller Deployment Models

A

Pyblic
Hybrid
Hybrid w/ private IPs

27
Q

SD-WAN Controller Deployment Model - Public

A

Use AWS or other public cloud providor

vSmart/vBond and vManage in multiple AWS regions

28
Q

SD-WAN Controller Deployment Model - Hybrid

A

Some vSmart/Manage/Bond in cloud
others in private data centers

Avoids issue of WAN circuits going down

29
Q

SD-WAN Controller Deployment Model - Hybrid w/ Private IP addresses

A

Some vSmart/Manage/Bond in cloud
others in private data centers

Private IP addresses used in PERSONAL Wan circuits

30
Q

Is it RECOMMENDED vSmart and vManage be behind 1:1 NAT

A

Yes, but not enforced

31
Q

Example of hardware SD-WAn can be deployed on

A

ISR&ASR series
ENCS 5000 series
CSR 1000V

32
Q

SD-WAN - zero touch provisioning

A

Devices (vEdges and cEdges) configured automatically (without involvement) when joining the network. Compoennts:

33
Q

What components allow ZTP in SD-WAN

A

Template configuraiton

Whitelist on vManage

34
Q

ZTP Router turn on process

A

1) Turns on
2) Connect to “ZTP Cloud Server” – Cisco Server
3) Gets vBond address

ZTP uses certificates for security of vManages and vSmarts