ENCOR Flashcards

(34 cards)

1
Q

SD WAN - what is the controller

A

vManage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

vManage is what type of itnerface

A

HTTP website

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

vSmart

A

Control plane

Pushes policies down to edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

vEdge

A

Edge Router in SD_WAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

vBond

A

Orchestrator - Zero-touch provisioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Newer cisco verison of vEdge

A

cEdge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SD-WAN - what topologoes is enabled with the most basic liences?

A

Hop and spoke

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SDWAN topologies

A

Hub and Spoke
Partial Mesh
Full mesh
PTP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In SD-WAN - What technologies enable application aware SLA(service-levelagreement)?

A

DPI

6-Tuple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

DPI stands for

A

Deep Packet Inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

6-Tuple refers too

A

6 Tuple is inspection of :

  • S,D IP
  • S,D Port
  • QoS -DSCP
  • IP protocol
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SD-WAN enables a user to deal with multiple WAN links, such as a leased line and MPLS circuit. What are the different SD-WAN configurations avaliable?

A

Active-Active
Active-Active (weighted)
Active-Standby (pinning)
Application-Aware SLA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SD-WAN : multiple WAN’s - Active-Active

A

Load balance across multiple WAN connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SD-WAN : multiple WAN’s - Active-Active (weighted)

A

Weighted Load balance across multiple WAN connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SD-WAN : multiple WAN’s - Active-Standby (pinning)

A

some applications always use one link, others (such as voice) always use one link

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SD-WAN : multiple WAN’s - Application-Aware SLA

A

Tracking metrics and responding

17
Q

SD-WAN - Protocol between vSmart and vEdge

A

OMP - Overlay Management Protocol

18
Q

OMP is responsible for telling …

A

telling vEdge/cEdge on how to create IPsec tunnels

19
Q

OMP uses what protocols

20
Q

bVond - Important considerations

A

Must have a public IP address

1:1 NAT

21
Q

Why is NAT traversal required in SD-WAN

A

IPsec tunnels are L3 so there is NO port numbers for the NAT to grab onto

22
Q

If NAT-T is enabled, what does SD-WAN do when it detects NAT is enabled

A

Switches from IPsec headers to UDP 4500

Allows NAT traversal

23
Q

What does vBond push new devices to vManage

A

Admins must approve new devices to ecosystem

Gets pushed to vSmart

24
Q

Why is vBond needed?

A

vSmart and vEdge don’t know about each other

25
How does vBond help with NAT travesal?
Both vEdge/cEdge on a side of a NAT firewall vBond sends packets at same time (knows public/private addresses) to each device which builds that NAT mappings OR vBond sends dummy packets
26
SD-WAN Controller Deployment Models
Pyblic Hybrid Hybrid w/ private IPs
27
SD-WAN Controller Deployment Model - Public
Use AWS or other public cloud providor | vSmart/vBond and vManage in multiple AWS regions
28
SD-WAN Controller Deployment Model - Hybrid
Some vSmart/Manage/Bond in cloud others in private data centers Avoids issue of WAN circuits going down
29
SD-WAN Controller Deployment Model - Hybrid w/ Private IP addresses
Some vSmart/Manage/Bond in cloud others in private data centers Private IP addresses used in PERSONAL Wan circuits
30
Is it RECOMMENDED vSmart and vManage be behind 1:1 NAT
Yes, but not enforced
31
Example of hardware SD-WAn can be deployed on
ISR&ASR series ENCS 5000 series CSR 1000V
32
SD-WAN - zero touch provisioning
Devices (vEdges and cEdges) configured automatically (without involvement) when joining the network. Compoennts:
33
What components allow ZTP in SD-WAN
Template configuraiton | Whitelist on vManage
34
ZTP Router turn on process
1) Turns on 2) Connect to “ZTP Cloud Server” – Cisco Server 3) Gets vBond address ZTP uses certificates for security of vManages and vSmarts