1toops
1toops
  • 164
  • 93 481
Cisco SD-WAN - MPLS only with Validator STUN Server (Spanish)
In this case, controllers are deployed on the private, MPLS network and control connections are established only through the MPLS network. An additional vBond is set up on the Internet so that Internet-connected devices can form data plane (IPSec and BFD sessions) with other devices over that transport.
The Validator on the Internet acts as a STUN server, which allows the WAN Edge router to discover its mapped, public IP address and port number on the Internet transport. This TLOC information (including the mapped public/private IP addresses) is exchanged over the private transport, which is then distributed to other WAN Edge routers, and data plane BFD sessions can be established to other WAN Edge routers over the Internet transport. No control traffic is sent or IPSec keys are exchanged over the Internet.
Note: This option requires at least a control connection to a vSmart controller over a single, separate transport, otherwise TLOC information cannot be exchanged in order to bring up IPSec and tunnels and BFD sessions with other WAN Edge routers over the Internet transport.
The WAN Edge device first sends a DNS request to resolve the Validator hostname. Both the publicly routable and private (RFC 1918) IP addresses are returned. The WAN Edge router will try both, but only the Validator on the Internet will be reachable via the publicly routable IP address and the Validator on the MPLS will be reachable via the private (RFC 1918) address.
The WAN Edge router on the Internet transport establishes a DTLS connection to the publicly routable IP address of the Validator and sends a STUN request to discover the WAN Edge post-NAT IP address. The WAN Edge device on the MPLS transport establishes a DTLS connection to the private, pre-NAT address of the vBond. The WAN Edge router then connects to the Manager and Controller using their private addresses because private color is used on the tunnels on both ends of the communication.
In this use case, the command vbond-as-stun-server is configured on the WAN Edge Internet tunnel interface. This option also requires the Validator domain name in the Validator configuration under system settings in the WAN Edge router to be translated by DNS into both a public and private IP address. Only the private IP address will be reachable on the MPLS side, and only the public IP address will be reachable on the Internet side. This can be done through a DNS server, or IP host names can be configured on the WAN Edge router under VPN 0 that translates the Validator hostname into multiple addresses, which includes both the public and private IP addresses.
#cisco
#sdwan
#vbond
#1toops
มุมมอง: 150

วีดีโอ

Cisco SD-WAN - Designing On-Prem Controllers (Spanish)
มุมมอง 1714 หลายเดือนก่อน
On-Prem Design Consideration • How to connect WAN Edge devices to controllers? • Internet • MPLS • Multiple Transports • Should I use private IPs, NAT, public IPs? • What transport colors should I assign to my controllers? • Where to place controllers in on-prem environment? #cisco #sdwan #onpremise
Cisco SD-WAN - OMP Control Policy IN/OUT (Spanish)
มุมมอง 2344 หลายเดือนก่อน
Cisco Catalyst SD-WAN devices advertise their local paths to the Cisco Catalyst SD-WAN Controller using OMP. Depending on the network topology, some paths might be advertised from multiple devices. Cisco Catalyst SD-WAN devices use the following algorithm to choose the best path. www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/routing/ios-xe-17/routing-book-xe/m-unicast-routing.html#b...
Cisco SD-WAN - OMP Best-Path Algorithm (Spanish)
มุมมอง 3366 หลายเดือนก่อน
Cisco Catalyst SD-WAN devices advertise their local paths to the Cisco Catalyst SD-WAN Controller using OMP. Depending on the network topology, some paths might be advertised from multiple devices. www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/routing/ios-xe-17/routing-book-xe/m-unicast-routing.html#best-path #cisco #sdwan #omp
Cisco SD-WAN - Microsoft Azure Virtual WAN Integration - Part 2 (Spanish)
มุมมอง 2297 หลายเดือนก่อน
Azure Virtual WAN is a networking service that brings many networking, security, and routing functionalities together to provide a single operational interface. Some of the main features include: - Branch connectivity (via connectivity automation from Virtual WAN Partner devices such as SD-WAN or VPN CPE). - Site-to-site VPN connectivity. - Remote user VPN connectivity (point-to-site). - Privat...
Cisco SD-WAN - Microsoft Azure Virtual WAN Integration - Part 1 (Spanish)
มุมมอง 5807 หลายเดือนก่อน
Azure Virtual WAN Hub Integration with Cisco Catalyst SD-WAN The integration of the Cisco Catalyst SD-WAN solution with Azure virtual WAN enhances Cloud OnRamp for Multicloud deployments and enables configuring Cisco Catalyst 8000V Edge Software (Cisco Catalyst 8000V) as a network virtual appliance (NVA) in Azure Virtual WAN Hubs. This integration simplifies the consumption model for cloud serv...
MS Azure & GNS3 On-prem - Site to Site VPN (Spanish)
มุมมอง 4858 หลายเดือนก่อน
This video shows you how to use the Azure portal to create a site-to-site VPN gateway connection between your on-premises network (GNS3 Lab) and a virtual network (VNet). learn.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-portal #microsoft #cisco #gns3
AZ-700 | Renew your Microsoft Certified: Azure Network Engineer Associate certification (Spanish)
มุมมอง 6119 หลายเดือนก่อน
If you’ve never renewed a certification before, here’s what you should know: 1. Certification renewal is free. 2. Renewal assessments are shorter than certification exams and focus only on recent technology updates. 3. You don’t need an appointment and there’s no proctor for renewal assessments. 4. There’s a flexible retake policy and instant feedback is provided upon completing the assessment....
Cisco SD-WAN - AAR | Preferred Color Group (Spanish)
มุมมอง 1859 หลายเดือนก่อน
Information About Configuring Path Preference Minimum releases: Cisco IOS XE Catalyst SD-WAN Release 17.9.1a, Cisco vManage Release 20.9.1 When configuring a centralized policy, you can create a preferred color group list, which specifies three levels of route preferences, called primary, secondary and tertiary. The route preferences are based on either or both of the following: - TLOC color - ...
Cisco SD-WAN - Umbrella - SIG Auto-Tunnel - Part 4 (Spanish)
มุมมอง 15010 หลายเดือนก่อน
Umbrella's cloud-delivered firewall (CDFW) provides firewall services without the need to deploy, maintain, and upgrade physical or virtual appliances at a site. The Umbrella CDFW supports visibility and control of internet traffic across branch offices. Umbrella logs all network activity and blocks unwanted traffic using IP, port, and protocol rule criteria.The firewall policy describes the ac...
Cisco SD-WAN - SD-AVC | Manager Cluster (Spanish)
มุมมอง 19510 หลายเดือนก่อน
Cisco SD-AVC is a component of Cisco Application Visibility and Control (AVC). It can be enabled on only one Cisco SD-WAN Manager server. The server on which it is enabled must have the Compute Data or the Compute persona. Cisco SD-AVC cannot be enabled on a server that has the Data persona. Note: If Cisco SD-WAN Manager is set up as a cluster and the cluster crashes as a result of a reboot or ...
Cisco SD-WAN - Umbrella - SIG Auto-Tunnel - Part 3 (Spanish)
มุมมอง 17911 หลายเดือนก่อน
ProcedureFollow the steps to configure and automatically deploy an IPsec tunnel in Cisco Catalyst SD-WAN. 1. Enable NAT in the outside interface (internet facing interface in VPN0). 2. Add one loopback interface for each IPsec tunnel. 3. Add an Umbrella SIG credentials feature template (legacy Umbrella Management API key and secret). 4. Add an Umbrella SIG tunnel feature template. 5. Link featu...
Cisco SD-WAN - SD-Routing Device Using Cisco SD-WAN Manager (Spanish)
มุมมอง 48811 หลายเดือนก่อน
This feature allows you to perform the basic management capabilities through Cisco SD-WAN Manager on the Cisco IOS XE devices that are operating in non-SD-WAN mode. From Cisco IOS XE 17.12.1a onwards, such devices will be referred as SD-Routing devices. You can use a single Network Management System (NSM) (Cisco SD-WAN Manager) to manage and monitor all the Cisco IOS XE routers and help in simp...
Cisco SD-WAN - Umbrella - SIG Auto-Tunnel - Part 2 (Spanish)
มุมมอง 10711 หลายเดือนก่อน
Global SIG Credentials Template Minimum supported release: Cisco vManage Release 20.9.1 In Cisco vManage Release 20.8.x and earlier releases, you must create a Cisco SIG Credentials template for a SIG provider (Cisco Umbrella or Zscaler) for each Cisco IOS XE Catalyst SD-WAN device model that you wish to connect to the SIG. From Cisco vManage Release 20.9.1, create a single global Cisco SIG Cre...
Cisco SD-WAN - Umbrella - SIG Auto-Tunnel - Part 1 (Spanish)
มุมมอง 17711 หลายเดือนก่อน
Cisco Catalyst SD-WAN (formerly known as Viptela) automates both the deployment of IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels with Umbrella and the IPsec configuration in cEdge and vEdge devices. Umbrella integrates with network devices that forward traffic from IPsec tunnels to the Umbrella data centers-the tunnel headend IP addresses-and connect to the...
Cisco SD-WAN - OMP and EIGRP Down-bit (Spanish)
มุมมอง 30411 หลายเดือนก่อน
Cisco SD-WAN - OMP and EIGRP Down-bit (Spanish)
Cisco SD-WAN - Upgrade Cisco Catalyst SD-WAN Manager Cluster to 20.12.x (Spanish)
มุมมอง 592ปีที่แล้ว
Cisco SD-WAN - Upgrade Cisco Catalyst SD-WAN Manager Cluster to 20.12.x (Spanish)
Cisco SD-WAN - Umbrella - Block Access to Web Site (Spanish)
มุมมอง 192ปีที่แล้ว
Cisco SD-WAN - Umbrella - Block Access to Web Site (Spanish)
Cisco SD-WAN - Umbrella - Download and Install the Roaming Client (Spanish)
มุมมอง 250ปีที่แล้ว
Cisco SD-WAN - Umbrella - Download and Install the Roaming Client (Spanish)
Cisco SD-WAN - Umbrella - Roaming Client Prerequisites (Spanish)
มุมมอง 86ปีที่แล้ว
Cisco SD-WAN - Umbrella - Roaming Client Prerequisites (Spanish)
Cisco SD-WAN - Umbrella - Roaming Client (Spanish)
มุมมอง 130ปีที่แล้ว
Cisco SD-WAN - Umbrella - Roaming Client (Spanish)
Cisco SD-WAN - vManage Cluster Creation (Spanish)
มุมมอง 402ปีที่แล้ว
Cisco SD-WAN - vManage Cluster Creation (Spanish)
Cisco SD-WAN - Clear vManage Stuck Task with an API Call (Spanish)
มุมมอง 202ปีที่แล้ว
Cisco SD-WAN - Clear vManage Stuck Task with an API Call (Spanish)
Cisco SD-WAN - QoS with TLOC Extension (Spanish)
มุมมอง 329ปีที่แล้ว
Cisco SD-WAN - QoS with TLOC Extension (Spanish)
Cisco SD-WAN - Umbrella - Best Practices for Policy Creation (Spanish)
มุมมอง 209ปีที่แล้ว
Cisco SD-WAN - Umbrella - Best Practices for Policy Creation (Spanish)
Cisco SD-WAN - Umbrella - Intelligent Proxy (Spanish)
มุมมอง 169ปีที่แล้ว
Cisco SD-WAN - Umbrella - Intelligent Proxy (Spanish)
Cisco SD-WAN - Umbrella - DNS-Layer Security basics (Spanish)
มุมมอง 451ปีที่แล้ว
Cisco SD-WAN - Umbrella - DNS-Layer Security basics (Spanish)
Cisco SD-WAN - Umbrella - Security Functions (Spanish)
มุมมอง 447ปีที่แล้ว
Cisco SD-WAN - Umbrella - Security Functions (Spanish)
Cisco SD-WAN - AURA Upgrade Readiness Experience (Spanish)
มุมมอง 256ปีที่แล้ว
Cisco SD-WAN - AURA Upgrade Readiness Experience (Spanish)
Linux Scripting - The sed Utility (Spanish)
มุมมอง 277ปีที่แล้ว
Linux Scripting - The sed Utility (Spanish)