Cisco Viptela SDWAN Licenses and propositions
- Fabric: Management, Controllers, ZTP
- Routing: Static & Topology: Hub-n-spoke only
- Internet/Cloud: NAT, Split tunnel, IPSec IKEv1/v2, GRE
- Policy: Local ACL only, Data policy, QoS
- SLA: Application aware routing (5 tuple only)
- Segmentation: 2 VPNs (service + transport)
- Visibility : DPI for visibility only, Support: 24x7x365, NBD RMA
- All Plus tier features
- Routing: Dynamic routing (OSPF/BGP)
- Topology: Mesh topology, any
- Internet/Cloud: Cloud on-ramp for IaaS/SaaS
- Policy: Control policy, service insertion, extra-net
- Segmentation: 5 VPNs (transport + 4x service)
- SLA: Application aware routing (DPI), Multicast
- All Professional tier features
- Segmentation: Unlimited VPNs
- Analytics: vAnalytics platform
- Optimizations: TCP Optimization
| Fig 1.2- Cisco Viptela SDWAN Fabric |
Single vSmart controller failure has no impact, if there is another vSmart controller vEdge routers are registered. If all vSmart controllers fail or become unreachable, vEdge routers will continue operating on a last known good state for a configurable amount of time (min of re-key timer and GR timer).
No updates to reachability
No IPsec re-key
No policy changes propagation
For service insertion features, Services layer (i.e.
Firewall) are part of underlay or overlay?
Physically, services are connected to vEdge routers and are advertised via
overlay network and become part of overlay network.
| Fig 1.3- Cisco Viptela SDWAN Single Service Insertion |
- vEdge router with connected L4-L7 service makes advertisement with service route OMP address family and service VPN label
- Service is advertised in specific VPN
- Service can be L3 routed or L2 bridged
- Service can be singly or dual connected (Firewall trust zones) to the advertising vEdge
- Control or data policies are used to insert the service node into the matching traffic forwarding path with match on 6-tuple or DPI signature and applied on ingress/egress vEdge
- vManage is multi-tenant (single VM instance or a cluster of 3 or more VM instances)
- Each vBond is multi-tenant, and a dedicated VM instance
- Each vSmart is single tenant. Each vSmart instance can either be deployed as a dedicated VM or inside a virtual container
- Each vEdge is single tenant