SD-WAN, SDA, Fabric Flashcards

SD-WAN, SD-Access, ACI

1
Q

Why type of Tunnels does SD-WAN leverage?

A

IPSec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the name of the device where SD-WAN Policy is defined?

A

The Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 main components of Cisco SD-WAN and what are their functions?

A

vManage - GUI and API VM used to configure and manage SD-WAN
vSmart - the controller that pushes the policy and acts as the data plane for the SD-WAN
vEdge / cEdge - These are the SD-WAN Edge Routers
vBond - the out of band orchestrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is cEdge and how is it different from vEdge?

A

cEdge is a Cisco ISR router running Viptella firmware. The main difference is that cEdge supports advanced security features that vEdge does not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What features does cEdge have that vEdge does not?

A
  • Cisco AMP and Threat Grid
  • Enterprise Firewall
  • Cisco Umbrella DNS
  • URL Filtering
  • Snort IPS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the three main features of vBond?

A
  • Control Plane Connection - permanent control plane connection to each vSmart controller
  • NAT Traversal
  • Load Balancing - load balances routers to vSmart controllers when more than one exist in a domain
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the benefits of SD-WAN?

A
  • Lower Costs and Reduce Risks with simple WAN automation and Orchestration
  • Extend Enterprise networks seamlessly into the public cloud
  • Provide optimal user experience for SaaS applications
  • Leverage a transport-independent WAN for lower cost and higher diversity. This means the underlay network can be any type of IP-based network, such as the Internet, MPLS, 3G/4G LTE, satellite, or dedicated circuits.
  • Enhance application visibility and use that visibility to improve performance with intelligent path control to meet SLAs for business-critical and real-time applications.
  • Provide end-to-end WAN traffic segmentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some limitations of Cisco SD-WAN?

A
  • Base SD-WAN license only allows for a Hub-and-Spoke topology
  • If there are two vManage, they must be Active/Passive
  • vAnalytics feature requires an additional license
  • vBond must have a public IP address (or NAT’d private)
  • Some ISR/ASR modules may not be compatible with cEdge
  • Deep Packet Inspection (DPI) requires additional licensing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the four different SD-WAN traffic forwarding options when configuring a policy?

A
  • Active/Active: Load Balanced
  • Active/Active Weighted: Load balanced based on bandwidth
  • Active/Standby Pinning: Application traffic has a preferred route unless it is down
  • Application Aware SLA: application traffic chooses a route based on network metrics such as loss and jitter
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In SD-WAN, what is OMP?

A

Overlay Management Protocol - this is the control plane information and controller policies that is sent from vSmart to the vEdge. Sent over TCP using SSL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the three different types of SD-WAN deployment models?

A
  • Public: on AWS
  • Hybrid: on-prem using Public IPs
  • Hybrid w/ Private IP: when ISP rejects public IP route
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a TLOC extension?

A

A connection between two vEdge routers at the same site that create a “U-shaped” topological connection to two redundant WAN links.

TLOC = Transport Locator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When deploying a vEdge or cEdge router using Zero Touch Provisioning (ZTP), what is the first thing the router attempts to communicate with?

A

A ZTP Server that is hosted and managed by Cisco on the Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When deploying a vEdge or cEdge router using Zero Touch Provisioning (ZTP), what are the only protocols enabled on the outside interface by default?

A

DNS, DHCP, and ICMP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

When DPI is not enabled in SD-WAN, what are the 6 parameters used to identify an application within a policy?

A

1 -2) Source and Destination IP address
3 - 4) Source and Destination Port
5) DSCP value (QoS)
6) Protocol Number

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When using Application Awareness and Deep Packet Inspection (DPI), what protocol is used to detect latency and jitter on a WAN circuit?

A

BFD - Bi-Directional Forwarding Detection

17
Q

In Cisco SD-WAN, what VPN ID is reserved for out-of-band management?

A

VLAN 512

18
Q

What is SD-WAN Cloud OnRamp for IaaS?

A

A feature that allows us to deploy virtual vEdge devices to IaaS platforms (AWS and Azure only) to bring SD-WAN into the public cloud.

19
Q

What is SD-WAN Cloud OnRamp for SaaS?

A

A feature that extends HTTP(S) probes to the SaaS platform to determine the best path to the SaaS.

20
Q

What is the name of the metric used to measure how good a connection is to an OnRamp SaaS application?

A

VQoE - Viptela Quality of Experience.

Value is 0 - 10

21
Q

What are the challenges of traditional networks that Software Defined Networks sets out to overcome?

A
  • Layer 2 Scaling in large networks
  • Layer 3 Roaming (Wireless)
  • CLI configuration in large networks (manual config)
  • Security and QoS
22
Q

What are the three elements that make up Cisco Campus Fabric when discussing SDN?

A
  • VXLAN - Tunnel
  • LISP - Routing
  • CTS (Cisco ISE)
23
Q

To create a Software Defined Network, what are the two critical entities?

A
  • Campus Fabric
  • DNA Center