0% found this document useful (0 votes)
8 views3 pages

Sdwan Basics

SD-WAN is a technology that simplifies WAN management by decoupling hardware from control mechanisms, utilizing centralized controllers for traffic routing based on policies and network conditions. Key components include Vmanage for management, VSmart for control plane information distribution, and VBond for device authentication. SD-WAN enhances performance through dynamic path selection, application-aware routing, and security integration, while leveraging overlay technologies for flexible network management.

Uploaded by

hamzaiqbal10277
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views3 pages

Sdwan Basics

SD-WAN is a technology that simplifies WAN management by decoupling hardware from control mechanisms, utilizing centralized controllers for traffic routing based on policies and network conditions. Key components include Vmanage for management, VSmart for control plane information distribution, and VBond for device authentication. SD-WAN enhances performance through dynamic path selection, application-aware routing, and security integration, while leveraging overlay technologies for flexible network management.

Uploaded by

hamzaiqbal10277
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

SD-WAN Components:

 Vmanage
 VSmart
 VBond
 VEdge
 CEdge

Vmanage: It is responsible for management Plane and all management related traffic will remain on
Vmanage. VEdge devives will be managed by the this [Link] this centralized controller
we can manage all the the WAN edge devices. We can manage;

 Centralized provisioning, policies and templates.


 Centralized trouble shooting and monitoring.
 Software updrades.
 It provides programme interfaces.
 It provides GUI and CLI access.
 1 Vmanage support 2000 edge devices.
 We can add 6 VManager is a single client.

VSmart:
 It distributes/reflects all control plane (router) related information to your WAN |Edge using
OMP (Overlay Mgt Plane) protocol.
 (i.e. edge devices will share routes with VSmart which will share these with other VEdge
devices).
 All policies for data traffic are defined centrally on Vmanage and distribute to WAN edge
using VSmart.
 It is a virtual appliance, not physical.
 VBond: Authenticate your edge devices using certificates and white list.
 It is responsible for distributing list of VSmart and Vmanage to all WAN Edge Devices.
 VBond should be publicallyy reachable.
 Static NAT required if VBond IP address is private.
 It is a virtual appliance, not physical.

Where we will deploy Controllers:


 Cloud Host (Amazon, AWS, Microsoft Azure, Google cloud.
 On Premises (VSphere Esxi, KVM, .qcow2)
VEdge/CEdge:
The WAN Edge devices will communicate to VSMart controller using OMP protocol to setup data
flow.

Software-Defined Wide Area Networking (SD-WAN) is a technology that simplifies the


management and operation of a wide area network (WAN) by decoupling the networking
hardware from its control mechanism. SD-WAN uses software-defined networking (SDN)
principles to dynamically manage the distribution of traffic across the WAN and to optimize
application performance.
Here's a high-level overview of how SD-WAN typically works:
Centralized Control and Management:
SD-WAN centralizes the control and management of the network through a centralized
controller or orchestrator.
The controller is responsible for making intelligent decisions about how to route traffic based
on policies and network conditions.
Overlay Network Creation:
SD-WAN creates a virtual overlay network on top of the existing physical network
infrastructure.
This overlay is often implemented using secure tunnels, such as IPsec or GRE tunnels, to
connect remote locations and data centers.
Dynamic Path Selection:
SD-WAN devices at each branch office (SD-WAN edge devices) dynamically assess the
network conditions, such as latency, packet loss, and available bandwidth.
Based on these conditions and predefined policies, the SD-WAN system intelligently selects
the optimal path for each application's traffic.
Application-Aware Routing:
SD-WAN is application-aware, meaning it can recognize different types of traffic and
prioritize them accordingly.
Critical applications, like VoIP or video conferencing, can be prioritized to ensure a better
user experience.
Hybrid WAN and Internet Breakout:
SD-WAN allows for the use of multiple network connections, including MPLS, broadband
internet, and LTE.
It can dynamically route traffic over the most appropriate link based on performance
requirements and cost considerations.
Internet breakout at the branch level enables direct access to the internet for certain traffic
instead of routing all traffic through the data center.
Security Integration:
SD-WAN often includes security features such as encryption, firewall capabilities, and threat
detection.
These security measures help protect data as it traverses the network, especially over public
internet connections.
Centralized Policy Management:
Policies for traffic routing, application performance, and security are centrally defined and
managed by the SD-WAN controller.
Changes to policies can be made centrally and pushed out to all SD-WAN edge devices,
ensuring consistency and ease of management.
In summary, SD-WAN works by leveraging software-defined networking principles to
optimize the performance and management of wide area networks. It provides organizations
with greater flexibility, agility, and control over their network infrastructure, particularly in
the context of connecting geographically distributed branch offices and data centers.

SD-WAN solutions typically utilize overlay technologies to create a virtual network layer
over the existing physical network infrastructure. This overlay network is designed to abstract
the underlying complexity of the physical network and enable more flexible and dynamic
management of network resources.
While there might not be a specific "Overlay Management Protocol" known by that name,
SD-WAN solutions commonly leverage various protocols to manage and optimize the
overlay network. Some of the protocols and technologies associated with SD-WAN include:
BGP (Border Gateway Protocol): BGP is often used for communication between SD-WAN
edge devices and for dynamic routing in overlay networks.
DMVPN (Dynamic Multipoint Virtual Private Network): DMVPN is a Cisco proprietary
solution that can be used in SD-WAN environments for secure communication between
remote sites.
IPsec (Internet Protocol Security): IPsec is frequently employed for securing communication
over the overlay network, providing encryption and authentication.
UDP (User Datagram Protocol) encapsulation: SD-WAN solutions might encapsulate traffic
using UDP for efficient transport over the overlay network.
It's worth noting that SD-WAN is a rapidly evolving field, and new protocols and standards
may have been introduced since my last update. If there have been changes or new
developments in the SD-WAN space, I recommend checking the latest documentation from
relevant vendors, standards organizations, or industry forums for the most recent information.

You might also like