Index

A

ACLs (access control lists), 112, 319320, 338

creating, 334335

effects of applying to localized policy, 338

referencing, 337

activating, centralized policies, 125127

address restricted cone NAT, 7677

administrative distances, WAN Edges, 60

AMP (Advanced Malware Protection), 349, 350351, 372377

dashboard, 376377

monitoring statistics, 375

policy configuration, 373374

APIs (application programming interfaces), 13

application lists, 118

application service containers, 360361

Application-Aware Enterprise Firewall, 349

actions, 355

dashboard, 359

destination zone, 353

firewall policies, 354

firewall policy, 353

inter-zone security, 356

intra-zone security, 355

monitoring statistics, 359

self-zone policy, 353

source zone, 353

zone pair, 353

zones, 352353

Application-Aware Routing, 350351

business imperative for, 286

application-based traffic engineering, 253254

application forwarding behavior without policy changes, 254

policy, 255257

steady and failed state, 258260

applications, protecting from packet loss, 269270

FEC (Forward Error Correction), 270274

packet duplication, 274280

applying changes to localized data policies, 337

App-Route policies

applying, 292

backup-sla-preferred color action, 314315

BFD (Bidirectional Forwarding Detection)

App-Route Multiplier, 300304

App-Route Poll Interval, 298300

liveliness detection, 295297

path quality monitoring, 298

settings, 303304

construction, 287294

mapping traffic flows to a transport tunnel, 304

mechanics, 286287

monitoring tunnel performance, 294

packet forwarding, 304

SLA class action, 306315

traditional lookup in the routing table, 305306

preferred color, 312

sample, 293294

sequence rules, 289

sequences, 309311

SLA class lists, 287

traffic forwarding configurations, 309315

App-Route Poll Interval, 298300

automatic provisioning, 102

automatic rollback, 91

automation, 2

B

B2B (business-to-business), 4

bandwidth, WANs, 9

best path selection, OMP, 5658

BFD (Bidirectional Forwarding Detection), 2829, 138, 294

liveliness detection, 295297

Hello Interval, 295297

Multiplier value, 297

path quality monitoring

App-Route Multiplier, 300304

App-Route Poll Interval, 298300

settings, 303304

BGP (Border Gateway Protocol), 466467

routing loop prevention, 6263

branch-to-branch communication, enabling

with summarization, 150152

with TLOC lists, 152168

brownouts, 56

BYOD (bring-your-own-device), 4, 18

C

C,I,R (chosen, installed, resolved), 51

calculating, ROI, 1718

CAs (certificate authorities), 494

CDFW (cloud-delivered firewall), 261

connectivity, 261263

SIG policy, 263267

validating service insertion, 266269

centralized control policies. See control policies

centralized data policies. See data policies

centralized policies, 110112, 117, 134136. See also control policies; data policies; localized policies

activation, 125127

application-aware routing, 112

cflowd, 112

construction, 118, 122125

control, 111

creating, 117118, 122125

and localized policies, 328

VPN membership, 111

certificates, 496501

automatic enrollment, 498501

generating, 511512

Cisco ACI (Application Centric Infrastructure), 18

Cisco ASR (Advanced Services Router), 30

Cisco Cloud, 38

Cisco IOS-XE, upgrading, 31

Cisco ISR (Integrated Services Router), 30

Cisco SD-WAN (Software-Defined WAN), 910, 387389. See also Application-Aware Enterprise Firewall; Cloud onRamp; control plane; data plane; management plane

automatic rollback, 91

Cloud onRamp, 394

configuration management, 91

control plane, 44

BFD, 2829

DTLS/TLS tunnels, 4546

encryption, 35

OMP, 44, 4748

OMP routes, 4851

path selection, 5658

security, 45

service routes, 5456

TLOC routes, 5254

vSmart, 3435

WAN Edges, 27, 28, 29, 32

controllers, 493494

data plane, 2732, 44, 65

address restricted cone NAT, 7677

encryption, 8384

full cone NAT, 74

key exchange process, 8486

NAT, 7374, 81

network segmentation, 8182

pairwise encryption keys, 8687

port restricted cone NAT, 7780

security, 6566

segmentation, 66

symmetric NAT, 7576

TLOC colors, 6670

tunnel groups, 7073

deployment options, 3839

design methodology, 459460

DIA, 3132

distributed architecture, 2627

DPI (Deep Packet Inspection), 400402

firewall policy, configuration, 356359

management plane, 44

vAnalytics, 3233

vManage, 3233

migrating to

branch design, 469

complete CE replacement, 470475

data center design, 462463

integration with branch firewall, 476478

integration with existing CE router, 475

integration with voice services, 478479

loopback TLOC design, 465466

overlay and underlay integration, 480489

preparation, 460462

service-side connectivity, 466469

transport-side connectivity, 463465

multi-tenancy options, 38

onboarding devices, 101102

automatic provisioning, 103105

manual bootstrapping of a WAN Edge, 102

orchestration plane, 3637, 44

physical platforms, 30

policies, 109. See also policies

centralized, 110112, 117118

construction, 115118

definition, 119122

domains, 113114

lists, 118119

localized, 112113

matching criteria, 120121

monitoring, 147

packet forwarding order of operations, 127128

purpose, 109110

saving, 147

on-premises deployment, 494

ROI, 1718

security suite, 349351, 361

AMP (Advanced Malware Protection), 372377

Application-Aware Enterprise Firewall, 352360

benefits, 351352

cloud security, 381383

DNS Web Layer security, 377381

IDS/IPS (intrusion detection and prevention), 360367

Threat Grid, 372377

URL filtering, 367372

vManage authentication and authorization, 384389

supported platforms, 3031

templates, 91, 9394

creating, 97101

device, 94, 9697

feature, 9495

options, 9697

values, 9596

transport independence, 1012

virtual platforms, 30

VPNs, 27

Cisco Umbrella, 377

DNS Web Layer security configuration, 378381

Cisco vEdges, 30

Cisco Webex, corporate direct cloud access, 243252

CLI (command line interface), 3, 2526

Cloud onRamp, 394

for Colocation, 429431, 432

cluster creation, 442448

IaaS integration, 438

image repository, 449

monitoring, 454455

network services, 432434

redundancy and high availability, 440

SaaS integration, 438440

service chain creation, 449454

service chain design best practices, 440441

service chaining for a single service node, 434436

service chaining for multiple service nodes, 436

for IaaS, 412418

configuration, 415426

transit VPCs, 413415

viewing VPC statistics, 426428

for SaaS, 394403

benefits, 395

configuration, 404412

DIA (Direct Internet Access), 395

hybrid deployment, 397

monitoring statistics, 398

prerequisites for all site types, 403

prerequisites for DIA or gateway sites, 404412

through a gateway, 397

vQoE score, 398399

cloud services, 4, 56

adoption, 19

challenges of, 393394

DIA (Direct Internet Access), 1516

private clouds, 38

security, 349, 381383

trends, 1921

VPC (virtual private cloud), 413

colocation, 432

color lists, 118

colors, 312

commands, 2526

encapsulation, 177

export-to, 211212, 220

local-tloc, 255

max-control-connections 0, 495496

preferred-color, 312

service, 263

service local, 266267

show app-route stats, 310

show bfd sessions, 73

show bfd summary, 151152

show ip bgp, 174

show omp routes, 175, 201202, 204206

show omp services, 56

show omp tlocs detail, 5354

show policy data-policy-filter, 241, 269

show policy from-vsmart, 241

show policy service-path, 250252, 269

show policy tunnel-path, 250252

show run omp, 59

show run vpn 10, 59

show running-config policy, 306, 313315, 344346

show tunnel statistics fec, 274

sla-class, 313

strict, 315

tloc-list, 255

traceroute, 138, 148149, 151152, 168, 190, 194195, 197198, 207

vpn, 507508

common desired benefits, WANs, 57

configuration management, 91

connectivity

CDFW (cloud-delivered firewall), 261263

WANs, 12

control plane, 3, 67, 2527, 44

DTLS/TLS tunnels, 4546

OMP, 44, 4748

attributes, 4950

graceful restart, 47

origin types, 5960

redistribution, 5860

routes, 4851

routing loop prevention, 6065

service routes, 5456

TLOC routes, 5254

path selection, 5658

security, 45

control policies, 111, 134136. See also localized policies

isolating remote branches from each other, 136149

monitoring, 147

multi-topology, 206210

saving, 147

use cases

creating different network topologies per segment, 206210

creating extranets and access to shared services, 211222

enabling branch-to-branch communication through data centers, 149152, 152168

enforcing security perimeters with service insertion, 195200

isolating guest users from the corporate WAN, 202206

isolating remote branches from each other, 136149

preferring regional data centers for Internet access, 180188

regional mesh networks, 188195

traffic engineering at sites with multiple routers, 169176, 177178

controllers. See also vBond; vManage; vSmart

authentication, 497

automatic enrollment for certificates, 498501

deployment

vBond, 513518

vManage, 501512

vSmart, 518522

obtaining a certificate, 498

on-premises deployment, 495496

whitelist files, 497498

counters, 241

creating

ACLs, 334335

App-Route policies, 287294

extranets, 211222

localized control policies, 325327

policies, 115118

centralized, 118, 122125

templates, 97101

credit card transactions, packet duplication, 274280

CRM (Customer Relationship Management), 9

CVVS (Common Vulnerability Scoring System), 363

D

dashboard

AMP (Advanced Malware Protection), 376377

Application-Aware Enterprise Firewall, 359

IDS/IPS, 366367

URL filtering, 371372

data centers, 4

data plane, 3, 67, 2532, 44, 65

encryption, 8384

key exchange process, 8486

pairwise encryption keys, 8687

NAT, 7374, 81

address restricted cone NAT, 7677

full cone, 74

port restricted cone, 7780

symmetric, 7576

security, 6566

segmentation, 66, 8182

TLOC colors, 6668

restrict keyword, 6870

tunnel groups, 7073

data policies, 114, 227, 228. See also App-Route policies; localized policies

App-Route, 285

backup-sla-preferred color action, 314315

BFD, 294304

construction, 287294

mapping traffic flows to a transport tunnel, 304

mechanics, 286287

monitoring tunnel performance, 294

packet forwarding, 304, 305315

preferred color, 312

sequences, 309311

traffic forwarding configurations, 309315

data prefix lists, 232233

editing, 235236

effects on users in the guest VPN, 239242

naming, 238

sequence types, 233235

use cases, 228229

application-based traffic engineering, 253260

direct cloud access for trusted applications, 243252

direct Internet access for guest users, 230242

protecting applications from packet loss, 269280

protecting corporate users with a cloud-delivered firewall, 261269

data prefix lists, 232233

decryption, pairwise keys, 8687

defining, policies, 119122

destination zone, 353

device templates, 94, 9697

adding localized control policy, 327330

setting TLOC preference, 177178

devices

provisioning

automatic, 103105

manual bootstrapping of a WAN Edge, 102

Viptela, 102

minimal configuration, 102103

DIA (Direct Internet Access), 1516, 3132, 349350, 395

direct cloud access for trusted applications, 243252

distributed architecture, 2627

DNS Web Layer security, 349, 377378

configuration, 378

security policy configuration, 378381

DTLS (Datagram Transport Layer Security), 3637, 4546

E

echo mode, BFD (Bidirectional Forwarding Detection), 2829

editing, data policies, 235236

EIGRP (Enhanced Interior Gateway Routing Protocol), routing loop prevention, 6365

encapsulation command, 177

encryption

data plane, 8384

key exchange process, 8486

pairwise encryption keys, 8687

vSmart, 35

end-to-end segmentation, 15

ERP (Enterprise Resource Planning), 9

export-to command, 211212, 220

extranets, creating, 211222

F

feature templates, 9495

FEC (Forward Error Correction), protecting applications from packet loss, 270274

FEC blocks, 271

firewall(s), 381. See also Application-Aware Enterprise Firewall

Application-Aware Enterprise Firewall

destination zone, 353

firewall policy, 353

self-zone policy, 353

source zone, 353

zone pair, 353

zones, 352353

cloud-delivered, 261

connectivity, 261263

SIG policy, 263267

validating service insertion, 266269

policies, 353, 354355, 356359

service insertion, 195200

full cone NAT, 74

G-H

graceful restart, 47

guest users, direct Internet access, 230242

Hello Interval, BFD (Bidirectional Forwarding Detection), 295297

hybrid WANs, 910

Active/Active, 13

I

IaaS (Infrastructure as a Service), 4, 56, 19

Cloud onRamp, 412418

configuration, 415426

transit VPCs, 413415

viewing VPC statistics, 426428

IBN (intent-based networking), 8

IDS/IPS (intrusion detection and prevention)

application service containers, 360361

configuration, 362363

dashboard, 366367

policy configuration, 365366

security virtual image upload, 364365

signature sets, 363364

Snort, 361

interactive video, 4

Internet access

for guest users, 230242

regionalizing, 180188

inter-zone security, 356

intra-zone security, 355

intrusion detection and prevention, 349

IoT (Internet of Things), 4, 18

IPsec (Internet Protocol Security), 27

IT industry

advances in, 12

automation, 2

trends, 45

K-L

KVM (Kernel Virtual Machines), 361

lists, 118119

SLA class, 287

liveliness detection, BFD (Bidirectional Forwarding Detection), 295297

Hello Interval, 295297

Multiplier value, 297

localized policies, 112113, 319320

and centralized policies, 328

control, 320322, 324

adding to the device template, 327330

creating, 325327

naming, 326327

route policy configuration, 322324, 325

viewing effects of route policies on neighboring routers, 333334

viewing route policies, 330332

data, 334

ACL, creating, 334335

ACL, referencing, 337

applying changes, 337

effects of applying an ACL, 338

previewing, 335336

QoS policy configuration, 338339

assign traffic to forwarding class, 339341

configure scheduling parameters for each queue, 341342

configure the transport interface with the QoS map, 343346

map forwarding classes to hardware queues, 341

map schedulers into a single QoS map, 342343

local-tloc command, 255

LxC (Linux Virtual Containers), 361

M

management plane, 67, 2527, 44

manually configured networks, risks, 23

max-control-connections 0 command, 495496

migrating to Cisco SD-WAN

branch design, 469

complete CE replacement, 470475

data center, 462463

integration with branch firewall, 476478

integration with existing CE router, 475

integration with voice services, 478479

loopback TLOC design, 465466

overlay and underlay integration

full overlay and underlay integration, 485489

overlay only, 480481

overlay with underlay backup, 481485

preparation, 460462

service-side connectivity, 466469

transport-side connectivity, 463465

mobile devices, 4

monitoring

centralized policies, 147

tunnel performance, 294

MPLS (Multiprotocol Label Switching), 1011

Multidomain, 1819

multi-tenancy, Cisco SD-WAN (Software-Defined WAN), 38

multi-topology policies, 206210

N

naming

data policies, 238

localized control policies, 326327

NAT (network address translation), 7374, 81

address restricted cone, 7677

full cone, 74

port restricted cone, 7780

symmetric, 7576

NAT fallback, 249250, 253

nat use-vpn 0 action, 249250, 253

network controllers, 3

networks. See also IBN (intent-based networking)

complexity, 8

redundancy, 7, 78

O

OMP (Overlay Management Protocol), 34, 44, 4748

graceful restart, 47

origin types, 5960

redistribution, 5860

route attributes, 4950

routing loop prevention

BGP, 6263

EIGRP, 6365

OSPF, 6062

service routes, 5456

status codes, 175

TLOC routes, 5254

onboarding devices, 101102

automatic provisioning, 103105

manual bootstrapping of a WAN Edge, 102

orchestration plane, 44

OSPF (Open Shortest Path First), routing loop prevention, 6062

overlay networks, 1011

P

packet duplication, 274280

packet forwarding, App-Route policies, 304

SLA class action, 306315

traditional lookup in the routing table, 305306

packet loss, protecting applications from, 269270

FEC (Forward Error Correction), 270274

packet duplication, 274280

pairwise encryption keys, 8687

parity packets, 271, 274

path quality monitoring, App-Route policies, 298

path selection, OMP, 5658

PnP (Plug and Play), 101102

policers, 119

policies. See also App-Route policies; centralized policies; control policies; data policies; localized policies

centralized, 110112, 117, 134136

activation, 125127

application-aware routing, 112

cflowd, 112

construction, 118, 122125

control, 111

isolating remote branches from each other, 136149

monitoring, 147

multi-topology, 206210

VPN membership, 111

construction, 115118

definition, 119122

domains, 113114

firewall, 354

lists, 118119

localized, 112113

matching criteria, 120121

packet forwarding order of operations, 127128

saving, 147

port restricted cone NAT, 7780

PoS (point of sales) systems, 56

preferred-color command, 312

prefix lists, 118119

on-premises deployment, 494

Cisco SD-WAN (Software-Defined WAN), 38

installation process, 495

previewing, localized data policies, 335336

private cloud deployment, Cisco SD-WAN (Software-Defined WAN), 38

Q

QoS (quality of service), 23, 56, 8, 112, 319320, 339

policies, configuration

assign traffic to forwarding class, 339341

configure scheduling parameters for each queue, 341342

configure the transport interface with the QoS map, 343346

map forwarding classes to hardware queues, 341

map schedulers into a single QoS map, 342343

R

redundancy, 7, 78

vSmart, 35

regional mesh networks, use case for centralized policies, 188195

regionalizing Internet access, 180188

RFC 4023, 27

RIB (Routing Information Base), 2627

risks, of manually configured networks, 23

ROI models, 1718

routers, 2526

routing loop prevention

BGP, 6263

EIGRP, 6365

OSPF (Open Shortest Path First), 6062

routing policies. See also policies, construction, 115118

S

SaaS (Software as a Service), 4, 56, 9, 19

Cloud onRamp

benefits, 395

configuration, 404412

DIA (Direct Internet Access), 395

hybrid deployment, 397

monitoring statistics, 398

prerequisites for all site types, 403

prerequisites for DIA or gateway sites, 404412

through a gateway, 397

vQoE score, 398399

saving, policies, 147

security

AMP (Advanced Malware Protection), 372377

dashboard, 376377

monitoring statistics, 375

policy configuration, 373374

Application-Aware Enterprise Firewall

actions, 355

dashboard, 359

firewall policy, 353

firewall policy configuration, 356359

inter-zone security, 356

intra-zone security, 355

monitoring statistics, 359

self-zone policy, 353

zone pair, 353

zones, 352353

benefits, 351352

cloud, 381383

control plane, 45

data plane, 6566

destination zone, 353

DIA (Direct Internet Access), 349350, 350

DNS Web Layer security, 377378

security policy configuration, 378381

IDS/IPS (intrusion detection and prevention), 360361

application service containers, 360361

configuration, 362363

CVVS, 363

dashboard, 366367

policy configuration, 365366

security virtual image upload, 364365

signature sets, 363364

policies, 112

Snort, 361

source zone, 353

Threat Grid, 372377

threat surface, 350

URL filtering, 350351, 367369

dashboard, 371372

policy configuration, 369371

vManage authentication and authorization

local authentication with RBAC, 384387

remote authentication with RBAC, 387389

WANs, 12

segmentation

data plane, 66, 8182

end-to-end, 15

self-zone policy, 353

sequences

App-Route policies, 309311

rules, App-Route policies, 289

types, data policies, 233235

service chaining, 5456

and the public cloud, 436

service command, 263

service insertion

CDFW (cloud-delivered firewall), 266269

firewall, 195200

service local command, 266267

service providers, 9

service routes, 5456

show app-route stats command, 310

show bfd sessions command, 73

show bfd summary command, 151152

show ip bgp command, 174

show omp routes command, 175, 201202, 204206

show omp services command, 56

show omp tlocs detail command, 5354

show policy data-policy-filter command, 241, 269

show policy from-vsmart command, 241

show policy service-path command, 250252, 269

show policy tunnel-path command, 250252

show run omp command, 59

show run vpn 10 command, 59

show running-config policy command, 306, 313315, 344346

show tunnel statistics fec command, 274

Simulate Flows tool, 182, 241, 243, 244, 248, 310

single points of failure, 7

sla-class command, 313

SLAs (service-level agreements), 67, 9, 14, 253

class action, 306308

class lists, 119, 287

App-Route policies, 308309

Snort, 361, 372

source zone, 353

strict command, 315

summarization, enabling branch-to-branch communication, 150152

symmetric NAT, 7576

T

TCP-Opt, 280

templates, 91, 9394

creating, 97101

device, 94, 9697

adding localized control policy, 327330

feature, 9495

options, 9697

values, 9596

Threat Grid, 349, 372377

policy configuration, 373374

TLOC lists, 119, 169

enabling branch-to-branch communication, 152168

tloc-list command, 166, 255

TLOCs (Transport Location Identifiers), 5254, 137138, 139140

colors, 6668

restrict keyword, 6870

loopback design, 465466

sequence rules, 142145

setting preferences

with centralized policy, 171176

with device templates, 177178

tloc-list, 166

TLS (Transport Layer Security), 4546

traceroute command, 138, 148149, 151152, 168, 190, 194195, 197198, 207

transit VPCs, 413415

transport independence, 912

trends

in cloud computing, 1921

in the IT industry, 45

trusted applications, direct cloud access, 243252

tunnel groups, 7073

U

upgrading, Cisco IOS-XE, 31

URL filtering, 349, 350351, 367369

dashboard, 371372

policy configuration, 369371

use cases

control policies

creating different network topologies per segment, 206210

creating extranets and access to shared services, 211222

enabling branch-to-branch communication through data centers, 149152, 152168

enforcing security perimeters with service insertion, 195200

isolating guest users from the corporate WAN, 202206

isolating remote branches from each other, 136149

preferring regional data centers for Internet access, 180188

regional mesh networks, 188195

traffic engineering at sites with multiple routers, 169176, 177178

data policies, 228229

application-based traffic engineering, 253260

direct cloud access for trusted applications, 243252

direct Internet access for guest users, 230242

protecting applications from packet loss, 269280

protecting corporate users with a cloud-delivered firewall, 261269

V

validating, CDFW service insertion, 266269

vAnalytics, 3233

vBond, 3637

deployment

add controller to vManage, 516518

initial bootstrap configuration, 514515

initial system configuration, 514

root certificate chain install, 515

VPN 0 and VPN 512 configuration, 515

version control, 91

video, 4, 56

Viptela devices, 508

minimal configuration, 102103

vManage, 32, 45, 353

authentication and authorization

local authentication with RBAC, 384387

remote authentication with RBAC, 387389

configuring Cloud onRamp for SaaS, 404412

deployment, 503505

apply initial bootstrap configuration, 506510

bootstrap and configure controller, 506

generate certificates, 511512

GUI, 142

initial system configuration, 507

New Policy Wizard, 140141

Real Time option, 137

VPN 0 and VPN 512 configuration, 508

whitelist files, 497

VPC (virtual private cloud), 413

vpn command, 507508

VPN lists, 119

VPNs, 1011, 27, 82

and VRFs, 28

zones, 352353

VRF (Virtual Routing and Forwarding), and VPNs, 28

vSmart, 3435, 44, 45, 57, 147

deployment

add controller to vManage, 520522

initial bootstrap configuration, 519520

displaying App-Route policy, 306308

encryption, 35

initial system configuration, 519

OMP, 34

redundancy, 35

root certificate chain install, 520

VPN 0 and VPN 512 configuration, 519520

W

WAN Edges, 27, 28, 29, 32, 35, 44, 70, 350351

administrative distances, 60

firewall, configuration, 197198

manual bootstrapping, 102

QoS policy configuration, 339

assign traffic to forwarding class, 339341

configure scheduling parameters for each queue, 341342

configure the transport interface with the QoS map, 343346

map forwarding classes to hardware queues, 341

map schedulers into a single QoS map, 342343

vBond, 3637

WANs, 45. See also Cisco SD-WAN (Software-Defined WAN); hybrid WANs

application support, 13

bandwidth, 9

common desired benefits, 57

connectivity, 12

redefining, 1213

security, 12

use cases demanding changes in

bandwidth aggregation and application load balancing, 1314

DIA (Direct Internet Access), 1516

end-to-end segmentation, 15

fully managed network solution, 1617

protecting critical applications with SLAs, 14

whitelist files, 497498

Z

zone pair, 353

zones, 352353

ZTP (Zero Touch Provisioning), 101102

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.216.239.46