Cisco SD-WAN Bring-Up: Controllers & Certificates
SD-WAN — Cisco Catalyst SD-WAN + Versa SD-WAN EVE-NG — vendor VMs
مقصدObjectiveObjective
اس لیب میں آپ controllers کو صحیح ترتیب میں bring-up کریں گے: پہلے vManage، پھر vBond، پھر vSmart — اور ہر ایک پر certificates انسٹال کریں گے۔Is lab mein aap controllers ko sahi tarteeb mein bring-up karenge: pehle vManage, phir vBond, phir vSmart — aur har aik par certificates install karenge.In this lab you will bring up the controllers in the correct order — vManage first, then vBond, then vSmart — and install certificates on each.
آسان مثالSimple AnalogySimple Analogy
پاسپورٹ آفس کی طرح: پہلے مرکزی دفتر (vManage) کھلتا ہے، پھر تصدیقی کاؤنٹر (vBond)، پھر پلاننگ آفس (vSmart)۔ ہر دفتر کو اپنا شناختی کارڈ (certificate) چاہیے ورنہ کوئی اس پر بھروسہ نہیں کرے گا۔Passport office ki tarah: pehle markazi daftar (vManage) khulta hai, phir tasdeeqi counter (vBond), phir planning office (vSmart). Har daftar ko apna shanakhti card (certificate) chahiye warna koi us par bharosa nahi karega.Like a passport office: the head office (vManage) opens first, then the verification counter (vBond), then the planning office (vSmart). Every office needs its own ID card (certificate), or nobody will trust it.
سیٹ اپLab SetupLab Setup
EVE-NG میں تین controller VMs اور ایک vEdge: vManage (10.0.0.1)، vBond (10.0.0.2)، vSmart (10.0.0.3) — سب ایک ہی management نیٹ ورک پر۔ Organization-name تینوں پر یکساں ہوگا: netsec-labs۔EVE-NG mein teen controller VMs aur aik vEdge: vManage (10.0.0.1), vBond (10.0.0.2), vSmart (10.0.0.3) — sab aik hi management network par. Organization-name teenon par yaksaan hoga: netsec-labs.In EVE-NG: three controller VMs and one vEdge — vManage (10.0.0.1), vBond (10.0.0.2), vSmart (10.0.0.3), all on the same management network. The organization-name will be identical on all three: netsec-labs.
اقداماتStepsSteps
Step 1
ترتیب یاد رکھیں: vManage پہلے، پھر vBond، پھر vSmart، آخر میں Edge۔ vManage پر basic system config لگائیں — یہی باقی سب کا حوالہ بنے گا۔Tarteeb yaad rakhen: vManage pehle, phir vBond, phir vSmart, aakhir mein Edge. vManage par basic system config lagayen — yehi baqi sab ka hawala banega.Remember the order: vManage first, then vBond, then vSmart, Edge last. Apply the basic system config on vManage — everything else references it.
config system host-name vmanage system-ip 10.0.0.1 site-id 100 organization-name netsec-labs vbond 10.0.0.2 ! commit exit
Step 2
vManage پر certificate انسٹال کریں۔ CSR بنائیں، اپنی enterprise CA سے sign کروائیں، پھر root CA chain سمیت انسٹال کریں۔ بغیر valid certificate کے کوئی control connection نہیں بنے گا۔vManage par certificate install karen. CSR banayen, apni enterprise CA se sign karwayen, phir root CA chain samet install karen. Baghair valid certificate ke koi control connection nahi banega.Install the certificate on vManage. Generate a CSR, get it signed by your enterprise CA, then install it along with the root CA chain. Without a valid certificate no control connection will form.
request certificate generate csr request certificate install signed-cert
🖱️ سرٹیفکیٹ انسٹال کرنے کا GUI راستہCertificate install karne ka GUI raastaConfiguration > Certificates > Controllers > Install Certificate
Step 3
اب vBond پر وہی system config لگائیں (اپنے system-ip 10.0.0.2 کے ساتھ) اور certificate انسٹال کریں۔ vBond کو vManage کا IP معلوم ہونا ضروری ہے۔Ab vBond par wahi system config lagayen (apne system-ip 10.0.0.2 ke saath) aur certificate install karen. vBond ko vManage ka IP maloom hona zaroori hai.Now apply the same system config on vBond (with its own system-ip 10.0.0.2) and install its certificate. vBond must know vManage's IP.
config system host-name vbond system-ip 10.0.0.2 site-id 100 organization-name netsec-labs vbond 10.0.0.2 ! commit exit
Step 4
vSmart پر system config اور certificate مکمل کریں (system-ip 10.0.0.3)۔ تینوں controllers پر organization-name حرف بہ حرف یکساں ہونا چاہیے۔vSmart par system config aur certificate mukammal karen (system-ip 10.0.0.3). Teenon controllers par organization-name harf ba harf yaksaan hona chahiye.Complete the system config and certificate on vSmart (system-ip 10.0.0.3). The organization-name must match character-for-character on all three controllers.
config system host-name vsmart system-ip 10.0.0.3 site-id 100 organization-name netsec-labs vbond 10.0.0.2 ! commit exit
Step 5
vEdge کو vBond کی طرف اشارہ دیں اور اسے activate کریں۔ vBond اس کا certificate چیک کر کے اسے vSmart اور vManage سے ملوائے گا — zero-touch کا یہی لمحہ ہے۔vEdge ko vBond ki taraf ishaara den aur usay activate karen. vBond uska certificate check kar ke usay vSmart aur vManage se milwayega — zero-touch ka yehi lamha hai.Point the vEdge at vBond and activate it. vBond will check its certificate and introduce it to vSmart and vManage — this is the zero-touch moment.
config system host-name vedge1 system-ip 10.0.1.1 site-id 10 organization-name netsec-labs vbond 10.0.0.2 ! commit exit
Step 6
تصدیق کریں: ہر controller پر control connections دیکھیں۔ سب کی state 'up' ہونی چاہیے اور vManage پر ساری services چل رہی ہونی چاہئیں۔Tasdeeq karen: har controller par control connections dekhen. Sab ki state 'up' honi chahiye aur vManage par saari services chal rahi honi chahiyen.Verify: check control connections on every controller. All states should be 'up', and all services should be running on vManage.
show control connections show certificate installed
🖱️ vManage میں ڈیوائسز دیکھنے کا راستہvManage mein devices dekhne ka raastaMonitor > Network (control connections table)
Step 7
vManage پر ڈیوائس کی فہرست دیکھیں — تینوں controllers اور vEdge نظر آنے چاہئیں۔ اگر کوئی غائب ہے تو اس کے certificate اور whitelist پر واپس جائیں۔vManage par device ki fehrist dekhen — teenon controllers aur vEdge nazar aane chahiyen. Agar koi ghaib hai to uske certificate aur whitelist par wapas jayen.View the device list on vManage — all three controllers and the vEdge should appear. If one is missing, go back to its certificate and the whitelist.
🖱️ ڈیوائس انوینٹری کا راستہDevice inventory ka raastaConfiguration > Devices (device inventory)
تصدیقVerifyVerify
ہر controller پر show control connections میں تمام peers 'up' ہوں۔ vManage پر request nms all status سے ساری services running ہوں۔Har controller par show control connections mein tamam peers 'up' hon. vManage par request nms all status se saari services running hon.On every controller, show control connections must list all peers as 'up'. On vManage, request nms all status must show all services running.
show control connections request nms all status
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Certificate install کے بعد بھی control connection down ہے۔Certificate install ke baad bhi control connection down hai.Control connection is still down after installing the certificate.
✅ سب سے پہلے clock/NTP چیک کریں — غلط وقت certificate کو invalid بنا دیتا ہے۔ پھر root CA chain انسٹال ہے یا نہیں، یہ دیکھیں۔Sab se pehle clock/NTP check karen — ghalat waqt certificate ko invalid bana deta hai. Phir root CA chain install hai ya nahi, ye dekhen.Check clock/NTP first — wrong time invalidates the certificate. Then confirm the root CA chain is installed.
⚠️ vEdge vBond سے رابطہ کر رہا ہے مگر authenticate نہیں ہو رہا۔vEdge vBond se rabta kar raha hai magar authenticate nahi ho raha.The vEdge reaches vBond but fails authentication.
✅ vBond کی whitelist میں ڈیوائس کا chassis-number/serial شامل کریں اور organization-name تینوں جگہ یکساں رکھیں۔vBond ki whitelist mein device ka chassis-number/serial shaamil karen aur organization-name teenon jagah yaksaan rakhen.Add the device's chassis-number/serial to vBond's whitelist and keep the organization-name identical everywhere.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Controllers کو کس ترتیب میں bring-up کرتے ہیں اور کیوں؟Controllers ko kis tarteeb mein bring-up karte hain aur kyun?In what order do you bring up the controllers, and why?
vManage پہلے (یہ management اور NMS ہے)، پھر vBond (orchestrator)، پھر vSmart، آخر میں Edge۔ ہر اگلا قدم پچھلے پر انحصار کرتا ہے۔vManage pehle (ye management aur NMS hai), phir vBond (orchestrator), phir vSmart, aakhir mein Edge. Har agla qadam pichhlay par inhesaar karta hai.vManage first (it is the management/NMS), then vBond (orchestrator), then vSmart, Edge last. Each step depends on the previous one.
❓ SD-WAN میں certificates کیوں ضروری ہیں؟SD-WAN mein certificates kyun zaroori hain?Why are certificates required in SD-WAN?
ہر ڈیوائس اور controller کی پہچان تصدیق کرنے کے لیے۔ بغیر valid certificate کے control connections نہیں بنتے اور کوئی ناجائز ڈیوائس overlay میں شامل نہیں ہو سکتی۔Har device aur controller ki pehchaan tasdeeq karne ke liye. Baghair valid certificate ke control connections nahi bantay aur koi najaiz device overlay mein shaamil nahi ho sakti.To authenticate the identity of every device and controller. Without a valid certificate no control connections form, and no rogue device can join the overlay.