cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2460
Views
10
Helpful
3
Replies

SD-WAN Survivability

rbncarvalho
Level 1
Level 1

Hi guys, 

 

Does anyone knows how long should an overlay fabric be up and running when it loses one of the controllers, for example:

  • vBond - How long can it be down
    • I know that if it is down, new routers or routers that we're down aren't able to join.
  • vSmart - How long can the network survive without this controller
    • Is this configurable somehow?
  • vManage - How long can it be down
    • all functions are up and running we lose management and change control, but how long can the routers be running without reaching the vManage.

I haven't tested it out by myself, but I can't also find any good documentation on this subject matter, 

 

Best Regards,
Please rate helpful posts,

Ruben Carvalho CCIE#57952
3 Replies 3

JW_UK
Level 1
Level 1

Hi  rbncarvalho,

 

My understanding is that SD-WAN fabric will stay up for the duration of the tunnel rekey interval.

 

vSmart's are responsible for distributing tunnel keys to routers that are participating in the fabric. If vSmart goes down and the tunnel key time expires the IPSEC tunnels will also go down.

The rekey interval is configured in the 'Security' feature template and the default time is 86400 seconds (24 hours). Therefore, by default, you would have 24 hours to recover your vSmart.

 

https://www.cisco.com/c/en/us/td/docs/routers/sdwan/command/sdwan-cr-book/config-cmd.html#wp5221204990 

 

rekey.JPG

 

Regards, JW

 

ekhabaro
Cisco Employee
Cisco Employee

vEdge will continue to hold routing information in the RIB unless gracefull-restart-timer expires:

 

https://sdwan-docs.cisco.com/Product_Documentation/Software_Features/Release_17.2/03Routing/02Configuring_OMP

 

By default, it's 12h, so you have 12h to recover your vSmart.

Hi guys, 

 

That makes sense, I was somehow aware of the 7 days, but I wasn't aware of the rekey timer, which is what makes it survive 7 days.

 

As for the vBond and vManage are there any time frame that the vEdges/cEdges need to reach any of these controllers?

 

Thank you, 

Best Regards, 

Best Regards,
Please rate helpful posts,

Ruben Carvalho CCIE#57952

Review Cisco Networking for a $25 gift card