[How To] Cisco SD-WAN - Onboarding a Catalyst 8000v (or CSR 1000v)

Поделиться
HTML-код
  • Опубликовано: 23 июл 2024
  • In this video, we'll walk through how to setup & onboard a Catalyst 8000v virtual router to a Cisco SD-WAN network. These steps also apply to a CSR 1000v router. Note that the configuration in this video is 100% manual, and does not use any day 0 auto-provisioning capabilities.
    Additional details in the blog: 0x2142.com/how-to-cisco-sd-wa...
    Links / Follow me elsewhere:
    - Blog: 0x2142.com
    - Twitter: / 0x2142
    - Mastodon/Fediverse: @matt@0x2142.com
    - GitHub: github.com/0x2142
    If this video was helpful to you, please consider subscribing & sharing! Thank you!
    Want to support this channel? Buy me a coffee: www.buymeacoffee.com/0x2142
    Thanks for watching!
    - Matt
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Chapters:
    0:00 - Intro
    0:55 - Lab Overview
    1:46 - Switching from Autonomous Mode to Controller-managed
    4:15 - SD-WAN System Config Settings
    5:35 - Interface & Tunnel Config
    6:45 - Loading a Self-Signed Enterprise CA Certificate
    8:53 - Generate OTP Token in vManage
    9:37 - Activating the Catalyst 8000v (& Validation)
    12:09 - Extra: Command Differences - 'show ip route' vs 'show sdwan ip route'
    Standard Disclaimer: Any comments / opinions here are my own, and do not represent my current or former employers.
  • НаукаНаука

Комментарии • 14

  • @rpratt7990
    @rpratt7990 5 месяцев назад +1

    Excellent video and great explanation! Thank you!

  • @andrewkemmy5909
    @andrewkemmy5909 Год назад +1

    I found this very helpful, thanks. In my case I depend on getting ssh access via GigabitEthernet1 so in my lab I added "allow-service all" within the configuration for the sdwan tunnel, otherwise ssh access is removed when the sdwan configuration is applied.

  • @peterg91
    @peterg91 Год назад +1

    Nice video, thanks.

  • @ie3957
    @ie3957 2 года назад

    good video, well done...is it normal behaviour that both Gig1 and tunnel int sharing same IP? would it be conflict? I tried this in my lab and I lost the box "although it's joined vmanage"

  • @seangodbehere1944
    @seangodbehere1944 Год назад

    I’m hitting an issue where after entering “controller-mode enable” and the device restarts, it boots back into autonomous mode. Have you seen that issue before?

  • @mohanmuthu677
    @mohanmuthu677 Год назад

    Good Video. But one question. After you issue the "activate" command on the CLI, how does this router learn the IP of the vManage? At this moment, the router only knows the IP of vBond. But router cannot authenticate to vBond because it does not have the certificate yet. So, my question is, how C8000v gets in touch with vManage for installing its certificate etc.?
    My search on Cisco documentation for this did not yield any results. I am sure you can help.
    Thanks a lot!

    • @0x2142
      @0x2142  Год назад

      Hello & Thanks for the comment. So the vBond acts as our onboarding server. The vBond uses the configured WAN edge list in vManage to know which edge devices are allowed to connect. When we issue the "activate" command, the router reaches out to vBond & asks for the vManage information. The token we provide in this step is used to help vBond authenticate the new device. Once allowed, vBond responds with the IP/domain of the other controllers. This allows the router to communicate with the vManage & vSmart servers - and get it's certificate from vManage.
      Hope that helps! There is additional information here: www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/SDWAN/sdwan-wan-edge-onboarding-deploy-guide-2020nov.pdf

    • @mohanmuthu677
      @mohanmuthu677 8 месяцев назад

      Thank you. I got that. Another question. At 9:47 at the activation command, the keyword 'vedge-cloud' is used, even though the platform we are activating is C8000V. Why?

  • @joand3512004
    @joand3512004 6 месяцев назад

    I can't add the 8000v image to eve-ng. It doesn't work

  • @noobsniperxx
    @noobsniperxx 2 года назад

    how did you get the unused device template?

    • @0x2142
      @0x2142  2 года назад

      Hi there - are you talking about this part? ruclips.net/video/HyPYLKrPPsk/видео.html
      If so, those unused devices are synced via your Cisco Smart Account. If you own licenses for a Catalyst 8000v - they should be in the Plug & Play portal, which you can sync to vManage.

    • @noobsniperxx
      @noobsniperxx 2 года назад

      Thanks. I figure it out. What version of the 8000v are you using cause I went they the steps but the 8000v didn’t call home to vManage. I’m using 20.5.1 for vManage and 17.x for the 8000v

    • @0x2142
      @0x2142  2 года назад

      For the Cat 8k, I was running 17.04.01 & I think vManage was also on 20.5

    • @noobsniperxx
      @noobsniperxx 2 года назад

      Ok. I must be missing something cause when I go to activate the 8000v didn’t doesn’t even try to reach out to vbond even though I can ping it