Capstone: Dual-Vendor SD-WAN Build
SD-WAN — Cisco Catalyst SD-WAN + Versa SD-WAN EVE-NG — vendor VMs
مقصدObjectiveObjective
اس capstone میں آپ ایک برانچ Cisco SD-WAN پر اور ایک Versa SD-WAN پر بنائیں گے، پھر checklist سے ثابت کریں گے کہ دونوں overlays صحیح routing، steering، encryption اور segmentation کرتے ہیں۔Is capstone mein aap aik branch Cisco SD-WAN par aur aik Versa SD-WAN par banayenge, phir checklist se sabit karenge ke donon overlays sahi routing, steering, encryption aur segmentation karte hain.In this capstone you will build one branch on Cisco SD-WAN and one on Versa SD-WAN, then walk a checklist proving both overlays route, steer, encrypt and segment correctly.
آسان مثالSimple AnalogySimple Analogy
دو ماڈل گھر آپس میں بنانے جیسا — ایک Cisco کی اینٹوں سے، دوسرا Versa کی اینٹوں سے۔ نقشہ ایک (dual WAN والی برانچ)، میٹیریل مختلف۔ Checklist ثابت کرتی ہے کہ دونوں گھر کھڑے ہیں۔Do model ghar aapas mein banane jaisa — aik Cisco ki eenton se, doosra Versa ki eenton se. Naksha aik (dual WAN wali branch), material mukhtalif. Checklist sabit karti hai ke donon ghar khare hain.Like building two model houses side by side — one from Cisco bricks, one from Versa bricks. Same blueprint (branch with dual WAN), different materials. The checklist proves both houses stand.
سیٹ اپLab SetupLab Setup
EVE-NG میں: مکمل Cisco stack (vManage, vSmart, vBond, 1 vEdge) اور مکمل Versa stack (Director, Controller, 1 CPE)۔ دونوں برانچز میں MPLS + Internet uplinks اور user LAN ہے۔EVE-NG mein: mukammal Cisco stack (vManage, vSmart, vBond, 1 vEdge) AUR mukammal Versa stack (Director, Controller, 1 CPE). Donon branches mein MPLS + Internet uplinks aur user LAN hai.In EVE-NG: full Cisco stack (vManage, vSmart, vBond, 1 vEdge) AND full Versa stack (Director, Controller, 1 CPE). Both branches have MPLS + Internet uplinks and a user LAN.
اقداماتStepsSteps
Step 1
دونوں stacks bring-up کریں: Cisco controllers (vManage → vBond → vSmart) certificates کے ساتھ، اور Versa Director + Controller CPE staging کے ساتھ۔ Lessons 2 اور 7 آپ کی recipe ہیں.Donon stacks bring-up karen: Cisco controllers (vManage → vBond → vSmart) certificates ke saath, aur Versa Director + Controller CPE staging ke saath. Lessons 2 aur 7 aapki recipe hain.Bring up both stacks: Cisco controllers (vManage → vBond → vSmart) with certificates, and Versa Director + Controller with the CPE staged. Use lessons 2 and 7 as your recipe.
Step 2
Control planes ثابت کریں: Cisco vEdge پر control connections up اور OMP میں TLOCs؛ Versa CPE Director پر reachable اور in-sync۔Control planes sabit karen: Cisco vEdge par control connections up aur OMP mein TLOCs; Versa CPE Director par reachable aur in-sync.Prove the control planes: Cisco vEdge shows control connections up and TLOCs in OMP; the Versa CPE shows reachable and in-sync on the Director.
show control connections show omp tlocs
🖱️ CPE reachable دیکھنے کا راستہCPE reachable dekhne ka raastaDirector > Monitor > Devices (CPE reachable)
Step 3
دونوں طریقوں سے configuration deploy کریں: Cisco device template vEdge سے attach، Versa device template workflow سے CPE پر۔ دونوں برانچز کو templates سے dual-WAN config ملے۔Donon tareeqon se configuration deploy karen: Cisco device template vEdge se attach, Versa device template workflow se CPE par. Donon branches ko templates se dual-WAN config mile.Deploy configuration both ways: Cisco device template attached to the vEdge, Versa device template deployed to the CPE via workflow. Both branches get dual-WAN config from templates.
🖱️ Templates لگانے کا راستہTemplates lagane ka raastaConfiguration > Templates > Device Templates (Cisco) | Director > Configuration > Templates (Versa)
Step 4
دونوں پر steering بنائیں: Cisco AAR data policy MPLS کو ترجیح دے Internet backup کے ساتھ؛ Versa SD-WAN policy rule وہی کرے۔ Business مقصد ایک، بولی دو۔Donon par steering banayen: Cisco AAR data policy MPLS ko tarjeeh de Internet backup ke saath; Versa SD-WAN policy rule wahi kare. Business maqsad aik, boli do.Build steering on both: Cisco AAR data policy preferring MPLS with Internet backup; Versa SD-WAN policy rule doing the same. Same business intent, two dialects.
🖱️ Policies لگانے کا راستہPolicies lagane ka raastaConfiguration > Policies (vSmart data policy) | Director > Configuration > Policies > SD-WAN (Versa)
Step 5
دونوں overlays پر encryption کی تصدیق کریں: Cisco tunnels پر pairwise IPsec SAs، Versa طرف encrypted overlay۔ WAN پر کہیں plaintext نہیں۔Donon overlays par encryption ki tasdeeq karen: Cisco tunnels par pairwise IPsec SAs, Versa taraf encrypted overlay. WAN par kahin plaintext nahi.Verify encryption on both overlays: pairwise IPsec SAs on the Cisco tunnels, encrypted overlay on the Versa side. No plaintext anywhere on the WAN.
show security ipsec sa
🖱️ Encryption چیک کرنے کا راستہEncryption check karne ka raastaDirector > Monitor > Security (tunnel encryption)
Step 6
دونوں برانچز کو segment کریں: guest segment جو user segment تک نہ پہنچ سکے — دونوں پلیٹ فارمز پر۔ Guest سے user کو ping کریں — دونوں stacks پر fail ہونا چاہیے۔Donon branches ko segment karen: guest segment jo user segment tak na pohanch sake — donon platforms par. Guest se user ko ping karen — donon stacks par fail hona chahiye.Segment both branches: a guest segment that cannot reach the user segment on either platform. Test ping from guest to user — it must fail on both stacks.
Step 7
آخری failover test: دونوں برانچز پر MPLS ایک ساتھ خراب کریں۔ دونوں پلیٹ فارمز پر voice/user ٹریفک Internet پر جانا چاہیے، اور MPLS ٹھیک ہونے پر واپس آنا چاہیے۔Aakhri failover test: donon branches par MPLS aik saath kharab karen. Donon platforms par voice/user traffic Internet par jana chahiye, aur MPLS theek hone par wapas aana chahiye.Final failover test: degrade MPLS on both branches at once. Voice/user traffic must steer to Internet on both platforms, then steer back when MPLS recovers.
show app-route stats
🖱️ Failover test دیکھنے کا راستہFailover test dekhne ka raastaDirector > Monitor > SD-WAN > Path Statistics
تصدیقVerifyVerify
Checklist تب مکمل جب: دونوں stacks پر control planes up، دونوں پر templates deployed، دونوں پر steering کام کرے (failover + recovery)، دونوں پر encryption verified، اور دونوں پر guest isolation قائم ہو۔Checklist tab mukammal jab: donon stacks par control planes up, donon par templates deployed, donon par steering kaam kare (failover + recovery), donon par encryption verified, aur donon par guest isolation qaim ho.Checklist complete when: control planes up on both stacks, templates deployed on both, steering works on both (failover + recovery), encryption verified on both, and guest isolation holds on both.
show control connections show app-route stats show security ipsec sa
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ایک پلیٹ فارم صحیح steer کرتا ہے دوسرا نہیں۔Aik platform sahi steer karta hai doosra nahi.One platform steers correctly but the other does not.
✅ دونوں کا rule-by-rule موازنہ کریں: SLA thresholds، rule order اور applied site/group۔ Business مقصد یکساں ہے — فرق ہمیشہ ان تینوں میں سے ایک میں ہوتا ہے۔Donon ka rule-by-rule mawazna karen: SLA thresholds, rule order aur applied site/group. Business maqsad yaksaan hai — farq hamesha in teenon mein se aik mein hota hai.Compare the two rule-by-rule: SLA thresholds, rule order and applied site/group. The business intent is identical — the mismatch is always in one of these three.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Cisco AAR اور Versa traffic steering کا موازنہ کریں۔Cisco AAR aur Versa traffic steering ka mawazna karen.How do Cisco AAR and Versa traffic steering compare?
Cisco AAR vSmart کی centralized data policy کے اندر ایک action ہے؛ Versa steering Director-managed CPE کی native SD-WAN policy rule ہے۔ تصور ایک، building block مختلف — اور آپ دونوں بنا چکے ہیں۔Cisco AAR vSmart ki centralized data policy ke andar aik action hai; Versa steering Director-managed CPE ki native SD-WAN policy rule hai. Tasawwur aik, building block mukhtalif — aur aap donon bana chuke hain.Cisco AAR is an action inside a centralized data policy on vSmart; Versa steering is a native SD-WAN policy rule on the CPE managed by Director. Same idea, different building block — and you have built both.
❓ Cisco کا segmentation approach Versa سے کیسے مختلف ہے؟Cisco ka segmentation approach Versa se kaise mukhtalif hai?How does Cisco's segmentation approach differ from Versa's?
مقصد ایک (الگ ٹریفک domains)، اوزار مختلف: Cisco service VPNs + centralized VPN topology استعمال کرتا ہے، Versa routing instances/VRFs + policy۔ Security کا نتیجہ برابر ہے۔Maqsad aik (alag traffic domains), auzaar mukhtalif: Cisco service VPNs + centralized VPN topology istemal karta hai, Versa routing instances/VRFs + policy. Security ka nateeja barabar hai.Same goal (isolated traffic domains), different tools: Cisco uses service VPNs + centralized VPN topology, Versa uses routing instances/VRFs + policy. The security outcome is equivalent.