🎤 SD-WAN — Interview Q&A

❓ SD-WAN میں تینوں planes سمجھائیں۔SD-WAN mein teenon planes samjhayen.Explain the three planes in SD-WAN.

Management plane (vManage: config، monitoring)، control plane (vSmart: routing decisions)، data plane (Edge: forwarding)۔ انہیں الگ کرنے سے control ڈیٹا سے آزاد scale ہوتا ہے۔Management plane (vManage: config, monitoring), control plane (vSmart: routing decisions), data plane (Edge: forwarding). Inhen alag karne se control data se azaad scale hota hai.Management plane (vManage: config, monitoring), control plane (vSmart: routing decisions), data plane (Edge: forwarding). Separating them lets control scale independently of data.

❓ OMP بمقابلہ BGP — فرق کیا ہے؟OMP vs BGP — farq kya hai?OMP vs BGP — what is the difference?

BGP autonomous systems کے درمیان راؤٹنگ کرتا ہے؛ OMP SD-WAN کا control پروٹوکول ہے جو vSmart سے Edge ڈیوائسز کو routes، TLOCs اور services کا اعلان control connections پر کرتا ہے۔BGP autonomous systems ke darmiyan routing karta hai; OMP SD-WAN ka control protocol hai jo vSmart se Edge devices ko routes, TLOCs aur services ka ilan control connections par karta hai.BGP routes between autonomous systems; OMP is the SD-WAN control protocol that advertises routes, TLOCs and services from vSmart to Edge devices over control connections.

❓ Cisco SD-WAN templates کیسے کام کرتے ہیں؟Cisco SD-WAN templates kaisay kaam karte hain?How do Cisco SD-WAN templates work?

Feature templates ایک function configure کرتے ہیں؛ device templates انہیں جوڑ کر مکمل config بناتے ہیں۔ Attach کرنے پر vManage سے config push ہوتی ہے — template ہمیشہ جیتتا ہے۔Feature templates aik function configure karte hain; device templates unhen jor kar mukammal config banate hain. Attach karne par vManage se config push hoti hai — template hamesha jeet-ta hai.Feature templates configure one function; device templates bundle them into a complete config. Attaching pushes the config from vManage — the template always wins.

❓ Application-aware routing کیا ہے؟Application-aware routing kya hai?What is application-aware routing?

AAR اصل وقت کی SLA (loss/latency/jitter) کی بنیاد پر ٹریفک steer کرتی ہے: جب preferred path SLA class توڑے تو flows خودبخود backup path پر چلے جاتے ہیں۔AAR asal waqt ki SLA (loss/latency/jitter) ke bunyad par traffic steer karti hai: jab preferred path SLA class tore to flows khud-ba-khud backup path par chale jate hain.AAR steers traffic by real-time SLA (loss/latency/jitter): when the preferred path violates the SLA class, flows move to the backup path automatically.

❓ Versa Director کیا کرتا ہے؟Versa Director kya karta hai?What does Versa Director do?

Versa Director management اور orchestration سنبھالتا ہے (vManage جیسا): onboarding، workflows، device groups، templates اور ڈیوائس lifecycle — سب کچھ ایک پلیٹ فارم پر۔Versa Director management aur orchestration sambhalta hai (vManage jaisa): onboarding, workflows, device groups, templates aur device lifecycle — sab kuch aik platform par.Versa Director handles management and orchestration (like vManage): onboarding, workflows, device groups, templates and device lifecycle — one platform for it all.

❓ SD-WAN اپنے tunnels کو کیسے secure کرتا ہے؟SD-WAN apne tunnels ko kaisay secure karta hai?How does SD-WAN secure its tunnels?

Pairwise keys: ہر tunnel کو vSmart سے اپنی key ملتی ہے، auto-rotate ہوتی ہے۔ ایک compromised key صرف ایک tunnel کو متاثر کرتی ہے — ایک shared key کے برعکس۔Pairwise keys: har tunnel ko vSmart se apni key milti hai, auto-rotate hoti hai. Aik compromised key sirf aik tunnel ko mutasir karti hai — aik shared key ke bar-aks.Pairwise keys: every tunnel gets its own key from vSmart, auto-rotated. One compromised key affects only one tunnel — unlike a single shared key.

❓ SD-WAN میں segmentation کیسے کام کرتی ہے؟SD-WAN mein segmentation kaisay kaam karti hai?How does segmentation work in SD-WAN?

الگ service VPNs (users، guests، IoT) ٹریفک domains کو isolate کرتے ہیں؛ vSmart پر VPN topology policy طے کرتی ہے کہ overlay میں کون کس سے بات کر سکتا ہے۔Alag service VPNs (users, guests, IoT) traffic domains ko isolate karte hain; vSmart par VPN topology policy tay karti hai ke overlay mein kaun kisse baat kar sakta hai.Separate service VPNs (users, guests, IoT) isolate traffic domains; VPN topology policy on vSmart controls who can talk to whom across the overlay.

❓ Tunnel down ہے۔ اپنی troubleshooting بتائیں۔Tunnel down hai. Apni troubleshooting batayen.A tunnel is down. Walk me through your troubleshooting.

اوپر سے نیچے: پہلے vManage alarms، پھر control connections، پھر OMP routes، پھر IPsec tunnel — نیچے جانے سے پہلے ہر layer CLI اور packet capture سے confirm کریں۔Oopar se neechay: pehle vManage alarms, phir control connections, phir OMP routes, phir IPsec tunnel — neechay jane se pehle har layer CLI aur packet capture se confirm karen.Top-down: check vManage alarms first, then control connections, then OMP routes, then the IPsec tunnel — confirm each layer with CLI and packet capture before moving down.