Sdwan Practice Lab 1 v1.1
Sdwan Practice Lab 1 v1.1
Sdwan Practice Lab 1 v1.1
PNETLAB Store
PNETLab.com
Lab Topology
1
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Table of Contents
VERSION HISTORY ......................................................................................................................................... 7
HOW TO SETUP LAB ...................................................................................................................................... 8
Hardware Requirement ............................................................................................................................ 8
Link to download lab and Setup ............................................................................................................. 10
Account login to the devices in the SD-WAN LAB................................................................................... 22
Lab 1: Configuring the WAN Components .................................................................................................. 24
Task 1 – HQ Router Configuration .......................................................................................................... 24
Task 2 – MPLS Cloud Router Configuration ............................................................................................ 25
Task 3- Internet Cloud Router Configuration .......................................................................................... 26
Lab 2: Installing the Enterprise Certificate Server ...................................................................................... 27
Task 1- Configure the interface............................................................................................................... 27
Task 2- Installing the Enterprise Root Certificate Server ........................................................................ 28
Task 2 Install WinSCP .............................................................................................................................. 34
Lab 3- Initializing vManage -CLI .................................................................................................................. 35
Task 1- Configuring the System Component........................................................................................... 35
Task 2- Configured the VPN parameters................................................................................................. 35
Lab 4- Initializing vManage – GUI................................................................................................................ 37
Task 1- Organization name & vBond Address......................................................................................... 37
Task 2 – Configure Controller Authorization as Enterprise Root and Download the Root Certificate. .. 37
Task 3- Generate a CSR for vManage...................................................................................................... 44
Task 4 – Request a Certificate from the CA Server ................................................................................. 46
Task 5 – Issue the Certificate from the CA Server................................................................................... 49
Task 6- Downloading the Issueed Certificate.......................................................................................... 50
Task 7- Installing the Identity Certificate for vManage........................................................................... 55
Lab 5- Initializing vBond – CLI ..................................................................................................................... 58
Task 1- Configuring the System component ........................................................................................... 58
Task 2 – Configure the vpn parameters .................................................................................................. 58
Lab 6- Initializing vBond -GUI ...................................................................................................................... 60
Task 1 – Add vBond to vManage............................................................................................................. 60
Task 2 – View the generated CSR for vBond and copy it ........................................................................ 61
Task 3- Request a certificate from the CA Server ................................................................................... 63
Task 4 – Issue the Certificate from the CA Server................................................................................... 66
2
Download PNETLab Platform
PNETLAB Store
PNETLab.com
3
Download PNETLab Platform
PNETLAB Store
PNETLab.com
4
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Lab 19 - Configuring Feature Templates –Service VPN – VPN, VPN Interface and Internal Routing –
Branch Site (vEdges).................................................................................................................................. 160
Task 1 - Configure a VPN Template to be used by all Branch vEdgeCloud Devices for VPN 1 ............. 160
Task 2 – Configure a VPN Interface Template to be used by all Branch vEdge-Cloud devices for VPN 1
for Interface G0/2 ................................................................................................................................. 161
Task 3 – Configure a OSPF Template to be used by all Branch vEdgeCloud Devices for VPN 1 ........... 163
Lab 20 - Implementing a Service VPN using Templates – Branch Site (vEdge2) ....................................... 165
Task 1 – Edit the BR-VE-TEMP Device Template for Branch vEdge Devices. ........................................ 165
Task 2 – Configure the Variable Parameters for the Feature Templates ............................................. 165
Lab 21 - Pushing Template to configure other Branch Sites - – Branch Site(vEdge3 & vEdge4) .............. 168
Task 1 – Attach the BR-VE-TEMP Device Template for Branch vEdge Devices..................................... 168
Lab 22 – Configuring Feature Templates for HQ-Site(vEdge1) – VPNs, VPN Interfaces, External & Internal
Routing ...................................................................................................................................................... 172
Task 1 – Configure a VPN Template for HQ vEdge-Cloud Devices for VPN 0 ....................................... 172
Task 2 – Configure a VPN Interface Template to be used by HQ vEdge-Cloud Devices for VPN 0 for
Interface G0/0 ....................................................................................................................................... 174
Task 3 – Configure a BGP Template to be used by HQ vEdge-Cloud Devices for VPN 0 ...................... 175
Task 1 – Configure a VPN Template to be used by HQ vEdge-Cloud Devices for VPN 512 .................. 178
Task 2 – Configure a VPN Interface Template to be used by HQ vEdge-Cloud Devices for VPN 512 for
Interface Eth0........................................................................................................................................ 180
Task 1 – Configure a VPN Template for HQ vEdge-Cloud Devices for VPN 1 ....................................... 182
Task 2 – Configure a VPN Interface Template to be used by HQ vEdge-Cloud Devices for VPN 1 for
Interface G0/2 ....................................................................................................................................... 184
Task 3 – Configure a OSPF Template to be used by HQ vEdge-Cloud Devices for VPN 1 ..................... 186
Lab 23 - Configuring Device Templates for HQ-Site(vEdge1) to deploy VPN 0, 1 and 512. ...................... 188
Task 1 – Configure a Device Template for HQ vEdge Devices. ............................................................. 188
Task 2 – Attach vEdge1 to the Device Template................................................................................... 190
Task 3 – Configure the Variable Parameters for the Feature Templates ............................................. 191
Lab 24 – Configuring Feature Templates for CSR – VPNs, VPN Interfaces, External & Internal Routing . 198
Task 1 – Configure a VPN Template by CSR for VPN 0 .......................................................................... 198
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 0 for Interface
GigabitEthernet1 ................................................................................................................................... 199
Task 3 – Configure a VPN Interface Template to be used by CSR for VPN 0 for Interface
GigabitEthernet3 ................................................................................................................................... 201
Task 4 – Configure a OSPF Template to be used by CSR for VPN 0 ...................................................... 203
5
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 1 – Configure a VPN Template to be used by CSR for VPN 512 .................................................... 204
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 512 for Interface
GigabitEthernet4 ................................................................................................................................... 206
Task 1 – Configure a VPN Template for CSR for VPN 1 ......................................................................... 208
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 1 for Interface G2 .............. 210
Task 3 – Configure a OSPF Template to be used by CSR for VPN 1 ...................................................... 212
Lab 25 - Configuring Device Templates for CSR to deploy VPN 0, 1 and 512 ........................................... 214
Task 1 – Configure a Device Template for CSR Branch Devices. ........................................................... 214
Task 2 – Attach cEdge1 to the Device Template ................................................................................... 218
Task 3 – Configure the Variable Parameters for the Feature Templates ............................................. 219
Lab 26 - Configuring and Deploying Feature and Device Templates for vSmart Controllers ................... 225
Task 1 – Configure a VPN Template to be used by vSmart Controllers for VPN 0................................ 225
Task 2 – Configure a VPN Template to be used by vSmart Controllers for VPN 512............................ 226
Task 3 – Configure a VPN Interface Template to be used by vSmart Controllers for VPN 0 for Interface
Eth1 ....................................................................................................................................................... 228
Task 4 – Configure a VPN Interface Template to be used vSmart Controllers for VPN 512 for Interface
Eth0 ....................................................................................................................................................... 229
Task 5 – Configure a Device Template for vSmart Controllers. ............................................................ 231
Task 6 – Attach vSmart to the Device Template ................................................................................... 233
Task 7 – Configure the Variable Parameters for the Feature Templates ............................................. 233
Lab 27 - Configuring Application Aware Policies using Telnet and Web .................................................. 236
Task 1 – Configure Groups of Interests/List that will be used for Telnet & Web Application Aware
Routing (AAR) Policy ............................................................................................................................. 236
Task 2 – Configure an AAR policy based on the Requirements ............................................................ 239
Task 3 – Create a Centralized Policy and call the Traffic Policy ............................................................ 242
Lab 28 - Manipulating Traffic flow using TLOCs ........................................................................................ 249
Task 1 – Configure Groups of Interests/List that will be used for Traffic Engineering Policy for DUBAI
.............................................................................................................................................................. 249
Task 2 – Configure Control/Topology policy based on the Requirements ........................................... 251
Task 3 – Modify the existing Centralized Policy “Main-CentralPolicy” and call the Topology Policy ... 252
Lab 29 - Configuring Route Filtering ........................................................................................................ 256
Task 1 – Configure Groups of Interests/List that will be used for Route Filtering Policy for Newyork 256
Task 2 – Configure Control/Topology policy based on the Requirements ........................................... 257
Task 3 – Modify the existing Centralized Policy “Main-CentralPolicy” and call the Topology Policy ... 258
6
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VERSION HISTORY
No Version Comment
1 1 Released workbook
Fixed:
+ Organization-name from “SDWAN” to "viptela sdwan"
2 1.1
+ Timer mismatched between Certificate and Controller
+ Correct ip address on E0/1 of HQ Router
7
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note: Recommended Rack Rental (if you do not have a PC or server to practice).
8
Download PNETLab Platform
PNETLAB Store
PNETLab.com
9
Download PNETLab Platform
PNETLAB Store
PNETLab.com
10
Download PNETLab Platform
PNETLAB Store
PNETLab.com
11
Download PNETLab Platform
PNETLAB Store
PNETLab.com
12
Download PNETLab Platform
PNETLAB Store
PNETLab.com
13
Download PNETLab Platform
PNETLAB Store
PNETLab.com
14
Download PNETLab Platform
PNETLAB Store
PNETLab.com
15
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note: If you are using PNETLab Version from 4.2.0, You do not need to do this step
16
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Step 3: Fixpermissions
o Login to PNETLab platform (note: logging with online account)
17
Download PNETLab Platform
PNETLAB Store
PNETLab.com
18
Download PNETLab Platform
PNETLAB Store
PNETLab.com
19
Download PNETLab Platform
PNETLAB Store
PNETLab.com
20
Download PNETLab Platform
PNETLAB Store
PNETLab.com
21
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note: Remember before you start the lab, wipe all nodes:
22
Download PNETLab Platform
PNETLAB Store
PNETLab.com
1. If you see all 4 vEdge and cEdge down in Vmanage, almost problem by Switch, you should stop
and start those switch
2. If only 4 vEdge down but cEdge are okay then you can start/stop 4 vEdges. Sometime they are
not stable in lab.
23
Download PNETLab Platform
PNETLAB Store
PNETLab.com
HQ
MPLS-Cloud
Interface-Cloud
HQ Router
hostname HQ
!
interface Ethernet0/0
ip address 100.1.1.1 255.255.255.0
!
interface Ethernet0/1
24
Download PNETLab Platform
PNETLAB Store
PNETLab.com
hostname MPLS
!
interface Ethernet0/0
ip address 10.1.11.2 255.255.255.0
!
interface Ethernet0/1
ip address 10.1.12.2 255.255.255.0
ip ospf network point-to-point
!
interface Ethernet0/2
ip address 10.1.13.2 255.255.255.0
ip ospf network point-to-point
!
interface Ethernet0/3
ip address 10.1.14.2 255.255.255.0
ip ospf network point-to-point
!
interface Ethernet1/0
ip address 10.1.15.2 255.255.255.0
ip ospf network point-to-point
25
Download PNETLab Platform
PNETLAB Store
PNETLab.com
!
router ospf 1
network 10.1.11.0 0.0.0.255 area 0
network 10.1.12.0 0.0.0.255 area 0
network 10.1.13.0 0.0.0.255 area 0
network 10.1.14.0 0.0.0.255 area 0
network 10.1.15.0 0.0.0.255 area 0
hostname Internet
!
no ip domain lookup
ip cef
!
interface Ethernet0/0
ip address 118.1.1.2 255.255.255.0
!
interface Ethernet0/1
ip address 118.1.2.1 255.255.255.0
!
interface Ethernet0/2
ip address 118.1.3.2 255.255.255.0
!
interface Ethernet0/3
ip address 118.1.4.2 255.255.255.0
!
interface Ethernet1/0
ip address 118.1.5.2 255.255.255.0
!
ip route 100.1.1.0 255.255.255.0 118.1.1.1
26
Download PNETLab Platform
PNETLAB Store
PNETLab.com
27
Download PNETLab Platform
PNETLAB Store
PNETLab.com
28
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Click Next
29
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Click Next
- Select “Certification authority Web enrollment” and click Next
30
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Leave the default for the Cryptography for CA and click Next
32
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Leave the default for the Validity Period and click Next
33
Download PNETLab Platform
PNETLAB Store
PNETLab.com
34
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note:
vManage
config
!
system
host-name vManage1
system-ip 100.1.1.12
site-id 1
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
!
commit
35
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vManage
config
!
vpn 0
no interface eth0
interface eth1
ip address 100.1.1.2/24
tunnel-interface
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 100.1.1.1
!
vpn 512
interface eth0
ip address 192.168.100.2/24
no shut
!
commit
36
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure Controller Authorization as Enterprise Root and Download the Root
Certificate.
- Browse to http://100.1.1.5/certsrv
- Click “Download Root Certificate”.
37
Download PNETLab Platform
PNETLAB Store
PNETLab.com
38
Download PNETLab Platform
PNETLAB Store
PNETLab.com
39
Download PNETLab Platform
PNETLAB Store
PNETLab.com
40
Download PNETLab Platform
PNETLAB Store
PNETLab.com
41
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Set the CSR Parameters with the Organization name, City, State, Country. Set the
Time to 3 Years and save.
42
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note: with sdwan version 20, You must uncheck “Set CSR Properties” due to the bug on the version
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp75927
43
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- It will open a windows with CSR. Copy by using CTRL-A and CTRL-C
44
Download PNETLab Platform
PNETLAB Store
PNETLab.com
45
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Select “Advanced”
46
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Paste the CSR in the box by using CTRL-V and click submit
47
Download PNETLab Platform
PNETLAB Store
PNETLab.com
48
Download PNETLab Platform
PNETLAB Store
PNETLab.com
49
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- The issued certificate link will show up. Click on the link
50
Download PNETLab Platform
PNETLAB Store
PNETLab.com
51
Download PNETLab Platform
PNETLAB Store
PNETLab.com
52
Download PNETLab Platform
PNETLAB Store
PNETLab.com
53
Download PNETLab Platform
PNETLAB Store
PNETLab.com
54
Download PNETLab Platform
PNETLAB Store
PNETLab.com
55
Download PNETLab Platform
PNETLAB Store
PNETLab.com
56
Download PNETLab Platform
PNETLAB Store
PNETLab.com
57
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Note:
vBond
config
!
system
host-name vBond1
system-ip 100.1.1.14
site-id 1
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4 local
!
commit
vBond
config
!
vpn 0
no interface eth0
58
Download PNETLab Platform
PNETLAB Store
PNETLab.com
interface ge0/0
ip address 100.1.1.4/24
tunnel-interface
encapsulation ipsec
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 100.1.1.1
!
vpn 512
interface eth0
ip address 192.168.100.4/24
no shut
!
commit
59
Download PNETLab Platform
PNETLAB Store
PNETLab.com
60
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- It will open a windows with CSR. Copy by using CTRL-A and CTRL-C
61
Download PNETLab Platform
PNETLAB Store
PNETLab.com
62
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Select “Advanced”
63
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Paste the CSR in the box by using CTRL-V and click Submit
64
Download PNETLab Platform
PNETLAB Store
PNETLab.com
65
Download PNETLab Platform
PNETLAB Store
PNETLab.com
66
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- The issued certificate link will show up. Click on the link
67
Download PNETLab Platform
PNETLAB Store
PNETLab.com
68
Download PNETLab Platform
PNETLAB Store
PNETLab.com
69
Download PNETLab Platform
PNETLAB Store
PNETLab.com
70
Download PNETLab Platform
PNETLAB Store
PNETLab.com
71
Download PNETLab Platform
PNETLAB Store
PNETLab.com
72
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- The Identity certificate should be installed for vBond and pushed to it.
73
Download PNETLab Platform
PNETLAB Store
PNETLab.com
74
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VSmart
config
!
system
host-name vSmart1
system-ip 100.1.1.13
site-id 1
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
!
commit
vSmart
config
!
vpn 0
no interface eth0
interface eth1
ip address 100.1.1.3/24
tunnel-interface
75
Download PNETLab Platform
PNETLAB Store
PNETLab.com
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 100.1.1.1
!
vpn 512
interface eth0
ip address 192.168.100.3/24
no shut
!
commit
76
Download PNETLab Platform
PNETLAB Store
PNETLab.com
77
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- It will open a window with CSR. Copy by using CTRL-A and CTRL-C
78
Download PNETLab Platform
PNETLAB Store
PNETLab.com
79
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Select “Advanced”
80
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Paste the CSR in the box by using CTRL-V and click Submit
81
Download PNETLab Platform
PNETLAB Store
PNETLab.com
82
Download PNETLab Platform
PNETLAB Store
PNETLab.com
83
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- The issued certificate link will show up. Click on the link
84
Download PNETLab Platform
PNETLAB Store
PNETLab.com
85
Download PNETLab Platform
PNETLAB Store
PNETLab.com
86
Download PNETLab Platform
PNETLAB Store
PNETLab.com
87
Download PNETLab Platform
PNETLAB Store
PNETLab.com
88
Download PNETLab Platform
PNETLAB Store
PNETLab.com
89
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- The Identity certificate should be installed for vSmart and pushed to it.
90
Download PNETLab Platform
PNETLAB Store
PNETLab.com
91
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Before doing this lab, please note that vedge have bug related to resolve the next-hop on vpn0. So
sometime, vmanage cant reach to vedge ➔ You must flap Ge0/0 or Ge0/1 interface.
- Select the file you downloaded from Section: HOW TO SETUP LAB > Link to download lab and
Setup > 2. How to setup and practice lab > licensing on SD-WAN Devices. Upload it and check
the Validate option.
92
Download PNETLab Platform
PNETLAB Store
PNETLab.com
93
Download PNETLab Platform
PNETLAB Store
PNETLab.com
94
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEDGE-1
Task 1 – Configuring the System Component
- Configure the System parameters based on the following:
o Host-name : vEdge1
o Organization: "viptela sdwan"
o System-IP: 119.1.1.21
o Site ID: 1
o vbond Address: 100.1.1.4
o Timezone: clock timezone America/Antigua
95
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEdge1
config
system
host-name vEdge1
system-ip 119.1.1.21
site-id 1
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
commit
vEdge1
config
vpn 0
no interface eth0
interface ge0/0
ip address 119.1.1.1/24
tunnel-interface
encapsulation ipsec
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 119.1.1.2
vpn 512
interface eth0
ip dhcp-client
no shutdown
commit
96
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEDGE-2
Task 1 – Configuring the System Component
- Configure the System parameters based on the following:
o Host-name : vEdge2
o Organization: "viptela sdwan"
o System-IP: 118.1.2.22
o Site ID: 2
o vbond Address: 100.1.1.4
o Timezone: Based on the appropriate Timezone
vEdge2
config
system
host-name vEdge2
system-ip 118.1.2.22
site-id 2
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
commit
vEdge2
config
vpn 0
no interface eth0
interface ge0/1
ip address 118.1.2.1/24
tunnel-interface
encapsulation ipsec
97
Download PNETLab Platform
PNETLAB Store
PNETLab.com
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 118.1.2.2
vpn 512
interface eth0
ip dhcp-client
no shutdown
!
commit
vEDGE-3
Task 1 – Configuring the System Component
- Configure the System parameters based on the following:
o Host-name : vEdge3
o Organization: "viptela sdwan"
o System-IP: 118.1.3.23
o Site ID: 3
o vbond Address: 100.1.1.4
o Timezone: Based on the appropriate Timezone
o Note: Default username: admin Default password: admin
vEdge3
config
!
system
host-name vEdge3
system-ip 118.1.3.23
site-id 3
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
!
commit
vEdge3
config
vpn 0
no interface ge0/0
interface ge0/1
ip address 118.1.3.1/24
tunnel-interface
encapsulation ipsec
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 118.1.3.2
vpn 512
interface eth0
ip dhcp-client
no shutdown
commit
vEDGE-4
Task 1 – Configuring the System Component
- Configure the System parameters based on the following:
o Host-name : vEdge4
o Organization: "viptela sdwan"
o System-IP: 118.1.5.25
o Site ID: 4
o vbond Address: 100.1.1.4
o Timezone: Based on the appropriate Timezone
vEdge4
config
system
host-name vEdge4
system-ip 118.1.5.25
site-id 4
organization-name "viptela sdwan"
clock timezone America/Antigua
vbond 100.1.1.4
99
Download PNETLab Platform
PNETLAB Store
PNETLab.com
commit
vEdge4
config
vpn 0
no interface ge0/0
interface ge0/1
ip address 118.1.4.1/24
tunnel-interface
encapsulation ipsec
allow-service all
allow-service netconf
allow-service sshd
no shut
ip route 0.0.0.0/0 118.1.4.2
vpn 512
interface eth0
ip dhcp-client
no shutdown
commit
100
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Copy the RootCert.cer file from the Downloads folder to the: /home/admin folder on the vEdge1
101
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEdge1:
102
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Note and use the Chassis Number and Token Number for the list vEdge from vManage
- Use the information from the previous step in the following command on the vEdge1 console.
vEdge1
103
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEDGE-2
Task 1 – Upload the Root Certificate to the vEdge
- On the Windows Server, open WINSCP application.
- Connect to vEdge2 using the following information:
o IP Address : 118.1.2.1
o Protocol - SFTP
o Username : admin
o Password : admin
104
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Copy the RootCert.cer file from the Downloads folder to the: /home/admin folder on the
vEdge2
105
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEdge2:
106
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Note and use the Chassis Number and Token number for the 2nd vEdge from vManage.
- Use the information from the previous step in the following command on the vEdge2 console
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- You should see the vEdge in the vManage console with a Certificate issued.
107
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEDGE-3
Task 1 – Upload the Root Certificate to the vEdge
- On the Windows Server, open WINSCP application.
- Connect to vEdge3 using the following information:
o IP Address : 118.1.3.1
o Protocol - SFTP
o Username : admin
o Password : admin
108
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Copy the RootCert.cer file from the Downloads folder to the: /home/admin folder on the
vEdge3
109
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEdge3:
110
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Note and use the Chassis Number and Token number for the 3nd vEdge from vManage.
- Use the information from the previous step in the following command on the vEdge3 console
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- You should see the vEdge in the vManage console with a Certificate issued.
111
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEDGE-4
Task 1 – Upload the Root Certificate to the vEdge
- On the Windows Server, open WINSCP application.
- Connect to vEdge4 using the following information:
o IP Address : 118.1.4.1
o Protocol - SFTP
o Username : admin
o Password : admin
112
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Copy the RootCert.cer file from the Downloads folder to the: /home/admin folder on the
vEdge4
113
Download PNETLab Platform
PNETLAB Store
PNETLab.com
vEdge4:
114
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Note and use the Chassis Number and Token number for the 3nd vEdge from vManage.
- Use the information from the previous step in the following command on the vEdge3 console
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
- You should see the vEdge in the vManage console with a Certificate issued.
115
Download PNETLab Platform
PNETLAB Store
PNETLab.com
116
Download PNETLab Platform
PNETLAB Store
PNETLab.com
cEdge1
config-transaction
hostname cEdge1
system
system-ip 118.1.5.25
site-id 5
organization-name "viptela sdwan"
vbond 100.1.1.4
exit
clock timezone America/Antigua
commit
117
Download PNETLab Platform
PNETLAB Store
PNETLab.com
cEdge1:
cEdge1
config-transaction
interface GigabitEthernet1
no shutdown
ip address 118.1.5.1 255.255.255.0
exit
ip route 0.0.0.0 0.0.0.0 118.1.5.2
interface Tunnel1
no shutdown
ip unnumbered GigabitEthernet1
tunnel source GigabitEthernet1
tunnel mode sdwan
exit
sdwan
interface GigabitEthernet1
tunnel-interface
encapsulation ipsec
color default
allow-service all
allow-service sshd
allow-service netconf
exit
exit
commit
118
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Connect to the console of cEdge1 and copy the RootCert.cer file to flash: using the following
command: copy tftp://100.1.1.5/RootCert.cer flash:
119
Download PNETLab Platform
PNETLAB Store
PNETLab.com
120
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Use the information from the previous step in the following command on the cEdge1 console.
- You should see the vEdge in the vManage console with a Certificate issued
121
Download PNETLab Platform
PNETLAB Store
PNETLab.com
122
Download PNETLab Platform
PNETLAB Store
PNETLab.com
123
Download PNETLab Platform
PNETLAB Store
PNETLab.com
124
Download PNETLab Platform
PNETLAB Store
PNETLab.com
125
Download PNETLab Platform
PNETLAB Store
PNETLab.com
126
Download PNETLab Platform
PNETLAB Store
PNETLab.com
127
Download PNETLab Platform
PNETLAB Store
PNETLab.com
128
Download PNETLab Platform
PNETLAB Store
PNETLab.com
129
Download PNETLab Platform
PNETLAB Store
PNETLab.com
130
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Lab 15 - Configuring Feature Templates -VPN & VPN Interfaces for VPN 0
& 512 ––Branch Site(vEdges)
Task 1 – Configure a VPN Template to be used by all Branch vEdgeCloud Devices for VPN
0
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vEdge Cloud ➔ VPN ➔ VPN
- Configure the VPN parameters based on the following:
o Template Name: BR-VE-VPN-VPN0
o Description: BR-VE-VPN-VPN0
Basic Configuration
o VPN ➔ Global: 0
o Name ➔ Global: Transport VPN
IPv4 Route
o Prefix ➔ Global: 0.0.0.0/0
o Next Hop ➔ Device Specific
- Click Save to save the Template.
131
Download PNETLab Platform
PNETLAB Store
PNETLab.com
132
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure a VPN Template to be used by all Branch vEdgeCloud Devices for VPN
512
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vEdge Cloud ➔ VPN ➔
VPN
- Configure the VPN parameters based on the following:
o Template Name: BR-VE-VPN-VPN512
o Description: BR-VE-VPN-VPN512
Basic Configuration
o VPN ➔ Global: 512
o Name ➔ Global: MGMT VPN
- Click Save to save the Template.
133
Download PNETLab Platform
PNETLAB Store
PNETLab.com
134
Download PNETLab Platform
PNETLAB Store
PNETLab.com
o NETCONF ➔ Global: On
o SSH ➔ Global: On
- Click Save to save the Template.
136
Download PNETLab Platform
PNETLAB Store
PNETLab.com
o NETCONF ➔ Global: On
o SSH ➔ Global: On
- Click Save to save the Template.
138
Download PNETLab Platform
PNETLAB Store
PNETLab.com
139
Download PNETLab Platform
PNETLAB Store
PNETLab.com
140
Download PNETLab Platform
PNETLAB Store
PNETLab.com
141
Download PNETLab Platform
PNETLAB Store
PNETLab.com
142
Download PNETLab Platform
PNETLAB Store
PNETLab.com
143
Download PNETLab Platform
PNETLAB Store
PNETLab.com
144
Download PNETLab Platform
PNETLAB Store
PNETLab.com
145
Download PNETLab Platform
PNETLAB Store
PNETLab.com
146
Download PNETLab Platform
PNETLAB Store
PNETLab.com
147
Download PNETLab Platform
PNETLAB Store
PNETLab.com
148
Download PNETLab Platform
PNETLAB Store
PNETLab.com
149
Download PNETLab Platform
PNETLAB Store
PNETLab.com
150
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Type Show Ip route on vEdge2 to verify that you are receiving OSPF routes from the MPLS
Router.
151
Download PNETLab Platform
PNETLAB Store
PNETLab.com
152
Download PNETLab Platform
PNETLAB Store
PNETLab.com
153
Download PNETLab Platform
PNETLAB Store
PNETLab.com
154
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Site-2
Interface IP Address Subnet Mask
E 0/0 172.172.1.2 255.255.255.0
Loopback1 192.168.21.1 255.255.255.0
Loopback2 192.168.22.1 255.255.255.0
Loopback3 192.168.23.1 255.255.255.0
Loopback4 192.168.234.2 255.255.255.255
Site-3
Interface IP Address Subnet Mask
E 0/0 172.173.1.2 255.255.255.0
Loopback1 192.168.31.1 255.255.255.0
Loopback2 192.168.32.1 255.255.255.0
Loopback3 192.168.33.1 255.255.255.0
Loopback4 192.168.234.3 255.255.255.255
Site-4
Interface IP Address Subnet Mask
E 0/0 172.174.1.2 255.255.255.0
Loopback1 192.168.41.1 255.255.255.0
Loopback2 192.168.42.1 255.255.255.0
Loopback3 192.168.43.1 255.255.255.0
Loopback4 192.168.234.4 255.255.255.255
Site-5
Interface IP Address Subnet Mask
E 0/0 172.175.1.2 255.255.255.0
Loopback1 192.168.51.1 255.255.255.0
Loopback2 192.168.52.1 255.255.255.0
Loopback3 192.168.53.1 255.255.255.0
155
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Site-1
no ip domain-loo
line con 0
logg sync
no exec-timeout
!
Hostname Site-1
!
Interface E 0/0
ip address 172.171.1.2 255.255.255.0
no shut
!
Interface Loopback1
ip address 192.168.11.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback2
ip address 192.168.12.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback3
ip address 192.168.13.1 255.255.255.0
ip ospf network point-to-point
!
router ospf 1
network 172.171.1.0 0.0.0.255 area 0
network 192.168.0.0 0.0.255.255 area 0
Site-2
no ip domain-loo
line con 0
logg sync
no exec-timeout
!
Hostname Site-2
!
Interface E 0/0
ip address 172.172.1.2 255.255.255.0
no shut
!
Interface Loopback1
ip address 192.168.21.1 255.255.255.0
156
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Site-3
no ip domain-loo
line con 0
logg sync
no exec-timeout
!
Hostname Site-3
!
Interface E 0/0
ip address 172.173.1.2 255.255.255.0
no shut
!
Interface Loopback1
ip address 192.168.31.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback2
ip address 192.168.32.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback3
ip address 192.168.33.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback4
ip address 192.168.234.3 255.255.255.255
ip ospf network point-to-point
!
router ospf 1
network 172.173.1.0 0.0.0.255 area 0
network 192.168.0.0 0.0.255.255 area 0
157
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Site-4
no ip domain-loo
line con 0
logg sync
no exec-timeout
!
Hostname Site-4
!
Interface E 0/0
ip address 172.174.1.2 255.255.255.0
no shut
Interface Loopback1
ip address 192.168.41.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback2
ip address 192.168.42.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback3
ip address 192.168.43.1 255.255.255.0
ip ospf network point-to-point
!
Interface Loopback4
ip address 192.168.234.4 255.255.255.255
ip ospf network point-to-point
!
router ospf 1
network 172.174.1.0 0.0.0.255 area 0
network 192.168.0.0 0.0.255.255 area 0
Site-5
no ip domain-loo
line con 0
logg sync
no exec-timeout
!
Hostname Site-5
!
Interface E0/0
ip address 172.175.1.2 255.255.255.0
ip ospf network point-to-point
no shut
!
Interface Loopback1
ip address 192.168.51.1 255.255.255.0
158
Download PNETLab Platform
PNETLAB Store
PNETLab.com
159
Download PNETLab Platform
PNETLAB Store
PNETLab.com
160
Download PNETLab Platform
PNETLAB Store
PNETLab.com
161
Download PNETLab Platform
PNETLAB Store
PNETLab.com
162
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 3 – Configure a OSPF Template to be used by all Branch vEdgeCloud Devices for VPN
1
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vEdge Cloud ➔ Other
Templates ➔ OSPF
- Configure the OSPF parameters based on the following:
o Template Name: BR-VE-OSPF-VPN1
o Description: BR-VE-OSPF-VPN1
Redistribution
o Protocol: OMP
- Area Configuration
o Area Number ➔ Global : 0
o Area Type ➔ Default
Interface Configuration
o Interface Name: Ge0/2
- Click Add to add the Interface and Click Add to add OSPF.
- Click Save to save the Template.
163
Download PNETLab Platform
PNETLAB Store
PNETLab.com
164
Download PNETLab Platform
PNETLAB Store
PNETLab.com
165
Download PNETLab Platform
PNETLAB Store
PNETLab.com
166
Download PNETLab Platform
PNETLAB Store
PNETLab.com
167
Download PNETLab Platform
PNETLAB Store
PNETLab.com
168
Download PNETLab Platform
PNETLAB Store
PNETLab.com
169
Download PNETLab Platform
PNETLAB Store
PNETLab.com
170
Download PNETLab Platform
PNETLAB Store
PNETLab.com
171
Download PNETLab Platform
PNETLAB Store
PNETLab.com
172
Download PNETLab Platform
PNETLAB Store
PNETLab.com
173
Download PNETLab Platform
PNETLAB Store
PNETLab.com
o NETCONF ➔ Global: On
o SSH ➔ Global: On
- Click Save to save the Template.
175
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Click Add to add the Interface and Click Add to add BGP Neighbor.
- Click Save to save the Template.
176
Download PNETLab Platform
PNETLAB Store
PNETLab.com
177
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VPN 512
Task 1 – Configure a VPN Template to be used by HQ vEdge-Cloud Devices for VPN 512
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vEdge Cloud ➔ VPN ➔ VPN
- Configure the VPN parameters based on the following:
o Template Name: HQ-VE-VPN-VPN512
o Description: HQ-VE-VPN-VPN512
Basic Configuration
o VPN ➔ Global: 512
o Name ➔ Global: MGMT VPN
- Click Save to save the Template.
178
Download PNETLab Platform
PNETLAB Store
PNETLab.com
179
Download PNETLab Platform
PNETLAB Store
PNETLab.com
180
Download PNETLab Platform
PNETLAB Store
PNETLab.com
181
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VPN 1
Task 1 – Configure a VPN Template for HQ vEdge-Cloud Devices for VPN 1
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vEdge Cloud ➔ VPN ➔ VPN
- Configure the VPN parameters based on the following:
o Template Name: HQ-VE-VPN-VPN1
o Description: HQ-VE-VPN-VPN1
Basic Configuration
o VPN ➔ Global: 1
o Name ➔ Global: Data VPN
- Click Save to save the Template.
182
Download PNETLab Platform
PNETLAB Store
PNETLab.com
183
Download PNETLab Platform
PNETLAB Store
PNETLab.com
184
Download PNETLab Platform
PNETLAB Store
PNETLab.com
185
Download PNETLab Platform
PNETLAB Store
PNETLab.com
186
Download PNETLab Platform
PNETLAB Store
PNETLab.com
187
Download PNETLab Platform
PNETLAB Store
PNETLab.com
188
Download PNETLab Platform
PNETLAB Store
PNETLab.com
189
Download PNETLab Platform
PNETLAB Store
PNETLab.com
190
Download PNETLab Platform
PNETLAB Store
PNETLab.com
191
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Type Show Ip route on vEdge2 to verify that you are receiving OSPF routes from the MPLS
Router.
- Type Show Ip route on Internal Site Routers to verify that you are receiving OSPF routes from
the other Sites.
- Verify reachability between the sites by Pinging the Internal Loopback to Loopback networks.
192
Download PNETLab Platform
PNETLAB Store
PNETLab.com
193
Download PNETLab Platform
PNETLAB Store
PNETLab.com
194
Download PNETLab Platform
PNETLAB Store
PNETLab.com
195
Download PNETLab Platform
PNETLAB Store
PNETLab.com
196
Download PNETLab Platform
PNETLAB Store
PNETLab.com
197
Download PNETLab Platform
PNETLAB Store
PNETLab.com
198
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 0 for Interface
GigabitEthernet1
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR1000v ➔ VPN ➔ VPN
Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name: BR-CSR-VPNINT-VPN0-G1
o Description: BR-CSR-VPNINT-VPN0-G1
Basic Configuration
o Shutdown ➔ Global: No
o Interface Name ➔ Global: GigabitEthernet1
o IPv4 Address ➔ Static ➔ Device Specific
Tunnel
o Tunnel Inteface ➔ Global: On
o Color ➔ Default
Allow Service
o All ➔ Global: On
o NETCONF ➔ Global: On
o SSH ➔ Global: On
- Click Save to save the Template.
199
Download PNETLab Platform
PNETLAB Store
PNETLab.com
200
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 3 – Configure a VPN Interface Template to be used by CSR for VPN 0 for Interface
GigabitEthernet3
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR1000v ➔ VPN ➔ VPN
Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name: BR-CSR-VPNINT-VPN0-G3
o Description: BR-CSR-VPNINT-VPN0-G3
- Basic Configuration
o Shutdown ➔ Global : No
o Interface Name ➔ Global: GigabitEthernet3
o IPv4 Address ➔ Static ➔ Device Specific
- Tunnel
o Tunnel Interface ➔ Global: On
o Color ➔ MPLS
- Allow Service
o All ➔ Global : On
201
Download PNETLab Platform
PNETLAB Store
PNETLab.com
o NETCONF ➔ Global : On
o SSH ➔ Global : On
- Click Save to save the Template.
202
Download PNETLab Platform
PNETLAB Store
PNETLab.com
203
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VPN 512
Task 1 – Configure a VPN Template to be used by CSR for VPN 512
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR1000v ➔ VPN ➔ Cisco
VPN
- Configure the VPN parameters based on the following:
- o Template Name : BR-CSR-VPN-VPN512
- o Description : BR-CSR-VPN-VPN512
- Basic Configuration
- o VPN ➔ Global : 512
- o Name ➔ Global : MGMT VPN
- Click Save to save the Template.
204
Download PNETLab Platform
PNETLAB Store
PNETLab.com
205
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 512 for Interface
GigabitEthernet4
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR1000v ➔ VPN ➔ Cisco
VPN Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name : BR-CSR-VPNINT-VPN512-G4
o Description : BR-CSR-VPNINT-VPN512-G4
Basic Configuration
o Shutdown ➔ Global: No
o Interface Name ➔ Global: GigabitEthernet4
o IPv4 Address ➔ Dynamic
- Click Save to save the Template
206
Download PNETLab Platform
PNETLAB Store
PNETLab.com
207
Download PNETLab Platform
PNETLAB Store
PNETLab.com
VPN 1
Task 1 – Configure a VPN Template for CSR for VPN 1
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR1000v ➔ VPN ➔ Cisco
VPN
- Configure the VPN parameters based on the following:
o Template Name : BR-CSR-VPN-VPN1
o Description : BR-CSR-VPN-VPN1
Basic Configuration
o VPN ➔ Global : 1
o Name ➔ Global : Data VPN
- Click Save to save the Template.
208
Download PNETLab Platform
PNETLAB Store
PNETLab.com
209
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure a VPN Interface Template to be used by CSR for VPN 1 for Interface G2
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ CSR ➔ VPN ➔ Cisco VPN
Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name : BR-CSR-VPNINT-VPN1-G2
o Description : BR-CSR-VPNINT-VPN1-G2
- Basic Configuration
o Shutdown ➔ Global : No
o Interface Name ➔ Global : GigabitEthernet2
o IPv4 Address ➔ Static -> Device Specific
- Click Save to save the Template.
210
Download PNETLab Platform
PNETLAB Store
PNETLab.com
211
Download PNETLab Platform
PNETLAB Store
PNETLab.com
212
Download PNETLab Platform
PNETLAB Store
PNETLab.com
213
Download PNETLab Platform
PNETLAB Store
PNETLab.com
214
Download PNETLab Platform
PNETLAB Store
PNETLab.com
215
Download PNETLab Platform
PNETLAB Store
PNETLab.com
216
Download PNETLab Platform
PNETLAB Store
PNETLab.com
217
Download PNETLab Platform
PNETLAB Store
PNETLab.com
218
Download PNETLab Platform
PNETLAB Store
PNETLab.com
219
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Verify the configuration on cEdge1. You can do that by verify OSPF Neighbor relationship with
the Internal Router by issuing the Show ip ospf neighbor command on cEdge1.
- Type Show Ip route on cEdge1 to verify that you are receiving OSPF routes from the MPLS
Router.
- Type Show Ip route on Internal Site Routers to verify that you are receiving OSPF routes from
the other Sites.
- Verify reachability between the sites by Pinging the Internal Loopback to Loopback networks.
220
Download PNETLab Platform
PNETLAB Store
PNETLab.com
221
Download PNETLab Platform
PNETLAB Store
PNETLab.com
222
Download PNETLab Platform
PNETLAB Store
PNETLab.com
223
Download PNETLab Platform
PNETLAB Store
PNETLab.com
224
Download PNETLab Platform
PNETLAB Store
PNETLab.com
225
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 2 – Configure a VPN Template to be used by vSmart Controllers for VPN 512
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vSmart ➔ VPN ➔ VPN
- Configure the VPN parameters based on the following:
o Template Name: vSmart -VPN-VPN512
o Description: vSmart -VPN-VPN512
Basic Configuration
o VPN ➔ Global : 512
o Name ➔ Global : MGMT VPN
- Click Save to save the Template.
226
Download PNETLab Platform
PNETLAB Store
PNETLab.com
227
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 3 – Configure a VPN Interface Template to be used by vSmart Controllers for VPN 0
for Interface Eth1
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vSmart ➔ VPN ➔ VPN
Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name: vSmart-VPNINT-VPN0-E1
o Description: vSmart-VPNINT-VPN0-E1
Basic Configuration
o Shutdown ➔ Global : No
o Interface Name ➔ Global : eth1
o IPv4 Address ➔ Static ➔ Device Specific
Tunnel
o Tunnel Inteface ➔ Global : On
o Color ➔ default
Allow Service
o All ➔ Global: On
o NETCONF ➔ Global: On
o SSH ➔ Global: On
- Click Save to save the Template.
228
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 4 – Configure a VPN Interface Template to be used vSmart Controllers for VPN 512
for Interface Eth0
- In vManage, Navigate to Configuration ➔ Templates ➔ Feature ➔ vSmart ➔ VPN ➔ VPN
Interface Ethernet
- Configure the VPN parameters based on the following:
o Template Name: vSmart-VPNINT-VPN512-E0
o Description: vSmart-VPNINT-VPN512-E0
Basic Configuration
o Shutdown ➔ Global: No
o Interface Name ➔ Global: eth0
o IPv4 Address ➔ Static ➔ Device-Specific
- Click Save to save the Template
229
Download PNETLab Platform
PNETLAB Store
PNETLab.com
230
Download PNETLab Platform
PNETLAB Store
PNETLab.com
231
Download PNETLab Platform
PNETLAB Store
PNETLab.com
232
Download PNETLab Platform
PNETLAB Store
PNETLab.com
233
Download PNETLab Platform
PNETLAB Store
PNETLab.com
234
Download PNETLab Platform
PNETLAB Store
PNETLab.com
235
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Dubai (Site-2) & Hongkong (Site-3) Sites should use the MPLS Transport for Telnet
- Traffic and the Biz-Internet Transport for Web Traffic.
- Telnet Should have a SLA based on the following:
o Loss – 5%
o Latency – 200
o Jitter – 100ms
- Web Should have a SLA based on the following:
o Loss – 10%
o Latency – 500
o Jitter – 100ms
- Create the Sites for Dubai and Hongkong.
- Create the VPN for VPN ID 1.
Task 1 – Configure Groups of Interests/List that will be used for Telnet & Web Application
Aware Routing (AAR) Policy
- In vManage, Navigate to Configuration ➔ Policies ➔ Custom Options ➔ Centralized Policy ➔
Lists.
- Click SLA Class and select New SLA Class list. Create 2 policies based on the following:
o Name: SLA-Telnet
o Loss: 30% (because in lab, packet lost is high)
o Latency: 200
o Jitter: 100ms
o Name: SLA-Web
o Loss: 40% (because in lab, packet lost is high)
o Latency: 500
o Jitter: 100ms
- Click VPN and select New VPN list. Create 1 policy based on the following:
o Name: VPN1
o ID: 1
- Click Site and select New Site list. Create 2 policies based on the following:
o Name: Dubai
o Site ID: 2
o Name: Hongkong
o Site ID: 3
236
Download PNETLab Platform
PNETLAB Store
PNETLab.com
237
Download PNETLab Platform
PNETLAB Store
PNETLab.com
238
Download PNETLab Platform
PNETLAB Store
PNETLab.com
239
Download PNETLab Platform
PNETLAB Store
PNETLab.com
o Color : biz-internet
o Backup Preferred Color: mpls
o Click Save Match and Actions to save the Sequence.
o Save the Policy.
240
Download PNETLab Platform
PNETLAB Store
PNETLab.com
241
Download PNETLab Platform
PNETLAB Store
PNETLab.com
242
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Verify the policy by using the Monitor ➔ Network ➔ vEdge3 ➔ Troubleshooting ➔ Simulate
Flows Tool.
- Telnet from Dubai or Hongkong should only use the mpls transport.
- Web from Dubai or Hongkong should only use the biz-internet transport.
- Normal Ping from Dubai or Hongkong should use both the Transports.
243
Download PNETLab Platform
PNETLAB Store
PNETLab.com
244
Download PNETLab Platform
PNETLAB Store
PNETLab.com
245
Download PNETLab Platform
PNETLAB Store
PNETLab.com
246
Download PNETLab Platform
PNETLAB Store
PNETLab.com
247
Download PNETLab Platform
PNETLAB Store
PNETLab.com
248
Download PNETLab Platform
PNETLAB Store
PNETLab.com
- Paris should only the MPLS TLOC as the preferred color while communicating to Dubai. The
Internet TLOC should be backup TLOC.
Task 1 – Configure Groups of Interests/List that will be used for Traffic Engineering Policy
for DUBAI
- In vManage, Navigate to Configuration ➔ Policies ➔ Custom Options ➔ Centralized Policy ➔
Lists.
- Click TLOCs and select New TLOC list. Create a policy based on the following:
o Name: DB-TLOC-MPLS-INT
o TLOC#1:
▪ IP Address: 118.1.2.22
▪ Color: MPLS
▪ Encapsulation: IPSec
▪ Preference: 300
o TLOC#2:
▪ IP Address: 118.1.2.22
▪ Color: Biz-internet
▪ Encapsulation: IPSec
▪ Preference: 200
249
Download PNETLab Platform
PNETLAB Store
PNETLab.com
250
Download PNETLab Platform
PNETLAB Store
PNETLab.com
251
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 3 – Modify the existing Centralized Policy “Main-CentralPolicy” and call the Topology
Policy
- In vManage, Navigate to Configuration ➔ Policies ➔ Custom Options ➔ Lists ➔ Site
- Create new site list Paris with site id 4.
252
Download PNETLab Platform
PNETLAB Store
PNETLab.com
253
Download PNETLab Platform
PNETLAB Store
PNETLab.com
254
Download PNETLab Platform
PNETLAB Store
PNETLab.com
255
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 1 – Configure Groups of Interests/List that will be used for Route Filtering Policy for
Newyork
- In vManage, Navigate to Configuration ➔ Policies ➔ Custom Options ➔ Centralized Policy ➔
Lists.
- Click Prefix and select New Prefix list. Create a policy based on the following:
o Name: PL-234
o Prefix List Entry: 192.168.234.0/24 le 32
- Click Site and select New Site list. Create a policy based on the following:
o Name : Newyork
o Site ID : 1
256
Download PNETLab Platform
PNETLAB Store
PNETLab.com
257
Download PNETLab Platform
PNETLAB Store
PNETLab.com
Task 3 – Modify the existing Centralized Policy “Main-CentralPolicy” and call the Topology
Policy
- In vManage, Navigate to Configuration ➔ Policies ➔ Custom Options ➔ Centralized Policy ➔
Main-Central-Policy ➔ Click “…” ➔ Edit.
- Click Topology on the Top of the page.
- Click Add Topology.
- Click “Import Existing” and select the PREF-234-NOT-2-NY from the drop-down list and click
Import.
- Click Policy Application on the Top of the page.
- Click the “Topology” tab.
- The PREF-234-NOT-2-NY will be there. Click “New Site” button.
- Select Newyork in the Outbound Site List.
- Click Add.
- Click the Save Policy button towards the button.
- Activate the policy.
- Wait for it to push the policy to the reachable vSmart Controller(s).
- Verify by using the Show IP route vpn 1 command on the Newyork vEdge (vEdge1).
- It should all the routes from the Branches except the 192.168.234.X/32routes.
- These routes should be present in the vEdge2, vEdge3 and vEdge4 routers. You can use the
Show IP route vpn 1 command to verify.
258
Download PNETLab Platform
PNETLAB Store
PNETLab.com
259
Download PNETLab Platform
PNETLAB Store
PNETLab.com
260
Download PNETLab Platform
PNETLAB Store
PNETLab.com
261