SD-WAN Monitoring, Troubleshooting & APIs
SD-WAN — Cisco Catalyst SD-WAN + Versa SD-WAN EVE-NG — vendor VMs
مقصدObjectiveObjective
اس لیب میں آپ vManage alarms، device events، vEdge پر packet capture اور vManage REST API استعمال کر کے overlay کی نگرانی اور troubleshooting کریں گے۔Is lab mein aap vManage alarms, device events, vEdge par packet capture aur vManage REST API istemal kar ke overlay ki nigrani aur troubleshooting karenge.In this lab you will use vManage alarms, device events, packet capture on a vEdge, and the vManage REST API to monitor and troubleshoot the overlay.
آسان مثالSimple AnalogySimple Analogy
ہسپتال کی طرح: alarm board (vManage alarms) emergencies بتاتا ہے، X-ray (packet capture) اندر کا حال دکھاتا ہے، patient records (logs) تاریخ بتاتے ہیں، اور pharmacy robot (REST API) حکم پر reports نکالتا ہے۔Hospital ki tarah: alarm board (vManage alarms) emergencies batata hai, X-ray (packet capture) andar ka haal dikhata hai, patient records (logs) tareekh batate hain, aur pharmacy robot (REST API) hukam par reports nikalta hai.Like a hospital: the alarm board (vManage alarms) flags emergencies, X-rays (packet capture) show what's inside, patient records (logs) tell the history, and the pharmacy robot (REST API) dispenses reports on command.
سیٹ اپLab SetupLab Setup
Lessons 1-9 کا مکمل لیب: controllers up، دو برانچ vEdge راؤٹرز templates، data policies اور VPNs کے ساتھ۔ آپ جان بوجھ کر چیزیں خراب کریں گے اور ڈھونڈیں گے۔Lessons 1-9 ka mukammal lab: controllers up, do branch vEdge routers templates, data policies aur VPNs ke saath. Aap jan-boojh kar cheezen kharab karenge aur dhoondhenge.The full lab from lessons 1-9: controllers up, two branch vEdge routers with templates, data policies and VPNs. You will deliberately break things and find them.
اقداماتStepsSteps
Step 1
vManage alarms page کھولیں۔ یہ ہمیشہ آپ کا پہلا قدم ہے: critical alarms (control down، cert expiring) بتاتے ہیں کہ CLI چھونے سے پہلے کہاں دیکھنا ہے۔vManage alarms page kholen. Ye hamesha aapka pehla qadam hai: critical alarms (control down, cert expiring) batate hain ke CLI chhune se pehle kahan dekhna hai.Open the vManage alarms page. It is always your first stop: critical alarms (control down, cert expiring) tell you where to look before you touch the CLI.
🖱️ Alarms دیکھنے کا راستہAlarms dekhne ka raastaMonitor > Alarms (vManage dashboard)
Step 2
EVE-NG میں ایک tunnel توڑیں (ایک WAN link shut کریں)، پھر vEdge پر stack چیک کریں: control connections → OMP summary → IPsec tunnel state۔ نوٹ کریں کہ سب سے پہلے کون سی layer fail ہوتی ہے۔EVE-NG mein aik tunnel toren (aich WAN link shut karen), phir vEdge par stack check karen: control connections → OMP summary → IPsec tunnel state. Note karen ke sab se pehle kaun si layer fail hoti hai.Break a tunnel in EVE-NG (shut one WAN link), then work the stack on the vEdge: control connections → OMP summary → IPsec tunnel state. Note which layer fails first.
show control connections show omp summary show ipsec tunnel
Step 3
WAN interface پر packet capture چلائیں۔ Peer کے IP پر filter لگائیں: tunnel up ہونے پر ESP packets نظر آنے چاہئیں، down ہونے پر صرف control ٹریفک۔WAN interface par packet capture chalayen. Peer ke IP par filter lagayen: tunnel up hone par ESP packets nazar aane chahiyen, down hone par sirf control traffic.Run a packet capture on the WAN interface. Filter for the peer's IP: you should see ESP packets when the tunnel is up, and only control traffic when it is down.
debug packet capture interface ge0/0 monitor traffic interface ge0/0
Step 4
REST API کا تصور آزمائیں: vManage پر authenticate کر کے session cookie لیں۔ یہاں سے GET /dataservice/device سے ہر ڈیوائس کی فہرست programmatically لے سکتے ہیں۔REST API ka tasawwur aazmayen: vManage par authenticate kar ke session cookie len. Yahan se GET /dataservice/device se har device ki fehrist programmatically le sakte hain.Try the REST API concept: authenticate to vManage and get a session cookie. From here you could GET /dataservice/device to list every device programmatically.
curl -k -X POST https://vmanage:8443/j_security_check -d 'j_username=admin&j_password=admin' -c cookie.txt
Step 5
اپنے توڑے ہوئے break کے اردگرد logs اور events پڑھیں۔ ہر log line کو step 1 کے alarm سے ملائیں — یہ ملانا ہی troubleshooting کی مہارت ہے۔Apne toray hue break ke ird-gird logs aur events parhen. Har log line ko step 1 ke alarm se milayen — ye milana hi troubleshooting ki maharat hai.Read the logs and events around your deliberate break. Match each log line to the alarm you saw in step 1 — this mapping is the troubleshooting skill.
show log | include ERROR show sdwan events
تصدیقVerifyVerify
ایک WAN link توڑ کر workflow ثابت کریں: vManage پر alarm آئے، صحیح CLI layer failure دکھائے، capture میں ESP رکتا نظر آئے، اور API ڈیوائس کو unreachable بتائے۔Aik WAN link tor kar workflow sabit karen: vManage par alarm aaye, sahi CLI layer failure dikhaye, capture mein ESP rukta nazar aaye, aur API device ko unreachable bataye.Break one WAN link and prove the workflow: alarm appears on vManage, the right CLI layer shows the failure, the capture shows ESP stopping, and the API lists the device as unreachable.
show control connections show ipsec tunnel
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ REST API 401 Unauthorized دے رہا ہے۔REST API 401 Unauthorized de raha hai.The REST API returns 401 Unauthorized.
✅ Session cookie expire ہو گئی یا credentials غلط ہیں۔ Fresh cookie کے لیے دوبارہ authenticate کریں، اور user کے پاس API/REST privileges ہوں۔Session cookie expire ho gayi ya credentials ghalat hain. Fresh cookie ke liye dobara authenticate karen, aur user ke paas API/REST privileges hon.The session cookie expired or credentials are wrong. Re-authenticate to get a fresh cookie, and check the user has API/REST privileges.
⚠️ Packet capture میں interface پر کوئی ٹریفک نہیں۔Packet capture mein interface par koi traffic nahi.Packet capture shows no traffic on the interface.
✅ غالباً غلط interface یا زیادہ سخت filter ہے۔ پہلے بغیر filter کے صحیح WAN interface capture کریں، پھر filter لگائیں۔Ghaliban ghalat interface ya zyada sakht filter hai. Pehle baghair filter ke sahi WAN interface capture karen, phir filter lagayen.You are probably capturing the wrong interface or an overly strict filter. Capture the correct WAN interface with no filter first, then narrow down.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Branch tunnel down کی رپورٹ کرتا ہے۔ آپ کی troubleshooting ترتیب کیا ہوگی؟Branch tunnel down ki report karta hai. Aapki troubleshooting tarteeb kya hogi?A branch reports a tunnel is down. What is your troubleshooting order?
vManage پر alarms اور device reachability دیکھیں، پھر control connections، پھر OMP routes، پھر data tunnel۔ Stack میں اوپر سے نیچے جائیں: management → control → data۔vManage par alarms aur device reachability dekhen, phir control connections, phir OMP routes, phir data tunnel. Stack mein oopar se neechay jayen: management → control → data.Check alarms and device reachability on vManage, then control connections, then OMP routes, then the data tunnel. Work down the stack: management → control → data.
❓ GUI کے بجائے SD-WAN APIs کیوں use کرو گے؟GUI ke bajaye SD-WAN APIs kyun use karoge?Why would you use SD-WAN APIs instead of the GUI?
Device status، alarms اور statistics programmatically نکالنے کے لیے — dashboards، خودکار health checks اور ticket creation بغیر GUI click کیے۔Device status, alarms aur statistics programmatically nikalne ke liye — dashboards, khudkar health checks aur ticket creation baghair GUI click kiye.To pull device status, alarms and statistics programmatically — dashboards, automated health checks and ticket creation without clicking through the GUI.