cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
511
Views
0
Helpful
5
Replies

SDWAN Onboarding

uni1389
Level 1
Level 1

Hello Team, 

I am trying to deploy SDWAN components on EVE-NG , but unfortunately am not able to see System-IP/IP information as shown in snapshot. The vManager cluster is working fine and i have installed certificate using Enterpsise CA and it shows only vManage/vBond only, not showing vSmart components.

Thanks in advance for your tips and feedback. 

uni1389_0-1704815978659.png

uni1389_2-1704816650894.png

 

uni1389_1-1704816068707.png

*****************************

vmanager01# show running-config system
system
host-name vmanager01
system-ip 30.255.255.1
site-id 250
admin-tech-on-failure
no vrrp-advt-with-phymac
sp-organization-name test.com
organization-name test.com
clock timezone Europe/Berlin
vbond vbond01.test.com

vpn 0
dns 200.250.250.100 primary
interface eth0
ip address 200.250.250.1/24
ipv6 dhcp-client
no shutdown
!
ip route 0.0.0.0/0 200.250.250.254

vpn 512
interface eth1
ip address 10.255.255.1/24
no shutdown
!
ip route 0.0.0.0/0 10.255.255.254
!
*****************************

vsmart01# show running-config system

system
host-name vSmart01
system-ip 30.255.255.11
site-id 250
admin-tech-on-failure
no vrrp-advt-with-phymac
sp-organization-name test.com
organization-name test.com
clock timezone Europe/Berlin
vbond vbond01.test.com

vpn 0
interface eth0
ip address 200.250.250.11/24
ipv6 dhcp-client
no shutdown
!
ip route 0.0.0.0/0 200.250.250.254
!
vpn 512
interface eth1
ip address 10.255.255.11/24
no shutdown
!
ip route 0.0.0.0/0 10.255.255.254
!

****************************

vbond01# show running-config system

system
host-name vbond01
system-ip 30.255.255.21
site-id 250
admin-tech-on-failure
no route-consistency-check
no vrrp-advt-with-phymac
sp-organization-name test.com
organization-name test.com
clock timezone Europe/Berlin
vbond vbond01.test.com local

vbond01# show running-config vpn 0
vpn 0
interface ge0/0
ip address 200.250.250.21/24
ipv6 dhcp-client
tunnel-interface
encapsulation ipsec
no allow-service bgp
allow-service dhcp
allow-service dns
allow-service icmp
allow-service sshd
allow-service netconf
allow-service ntp
no allow-service ospf
no allow-service stun
allow-service https
!
no shutdown
!
ip route 0.0.0.0/0 200.250.250.254
!

vpn 512
interface eth0
ip address 10.255.255.21/24
ipv6 dhcp-client
no shutdown
!
ip route 0.0.0.0/0 10.255.255.254
!
****************************

 

with many regards

 

 

 

5 Replies 5

uni1389
Level 1
Level 1

uni1389_0-1704817157884.png

uni1389_1-1704817201259.png

 

Torbjørn
Spotlight
Spotlight

The vsmart also needs a VPN 0 tunnel interface with the netconf service allowed.

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

Hi,

share show control connections to understand whether there is control connections between vmanages and vsmarts

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

In vsmart you dont config dns so it can not resolve vbond ip

MHM

Hi , I have the following info . Even all SD-WAN components are reachable to eachother and vBonds not showing any OMP routes and neighbor. 

Thanks for your feedback. 

****************************************************************************************************************************
****************************************************************************************************************************
vbond# show orchestrator connections
PEER PEER
PEER PEER PEER SITE DOMAIN PEER PRIVATE PEER PUBLIC ORGANIZATION
INSTANCE TYPE PROTOCOL SYSTEM IP ID ID PRIVATE IP PORT PUBLIC IP PORT REMOTE COLOR STATE NAME UPTIME
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
0 vsmart dtls 30.255.255.11 250 1 200.250.250.11 12346 200.250.250.11 12346 default up test.com 0:00:26:05
0 vsmart dtls 30.255.255.11 250 1 200.250.250.11 12446 200.250.250.11 12446 default up test.com 0:00:26:09
0 vsmart dtls 30.255.255.12 250 1 200.250.250.12 12346 200.250.250.12 12346 default up test.com 0:00:25:55
0 vsmart dtls 30.255.255.12 250 1 200.250.250.12 12446 200.250.250.12 12446 default up test.com 0:00:25:55
0 vsmart dtls 30.255.255.13 250 1 200.250.250.13 12346 200.250.250.13 12346 default up test.com 0:00:26:02
0 vsmart dtls 30.255.255.13 250 1 200.250.250.13 12446 200.250.250.13 12446 default up test.com 0:00:26:06
0 vmanage dtls 30.255.255.1 250 0 200.250.250.1 12346 200.250.250.1 12346 default up test.com 0:00:26:00
0 vmanage dtls 30.255.255.1 250 0 200.250.250.1 12446 200.250.250.1 12446 default up test.com 0:00:25:54
0 vmanage dtls 30.255.255.1 250 0 200.250.250.1 12546 200.250.250.1 12546 default up test.com 0:00:26:06
0 vmanage dtls 30.255.255.1 250 0 200.250.250.1 12646 200.250.250.1 12646 default up test.com 0:00:26:07
0 vmanage dtls 30.255.255.2 250 0 200.250.250.2 12346 200.250.250.2 12346 default up test.com 0:00:25:37
0 vmanage dtls 30.255.255.2 250 0 200.250.250.2 12446 200.250.250.2 12446 default up test.com 0:00:25:56
0 vmanage dtls 30.255.255.2 250 0 200.250.250.2 12546 200.250.250.2 12546 default up test.com 0:00:26:05
0 vmanage dtls 30.255.255.2 250 0 200.250.250.2 12646 200.250.250.2 12646 default up test.com 0:00:26:05
0 vmanage dtls 30.255.255.3 250 0 200.250.250.3 12346 200.250.250.3 12346 default up test.com 0:00:25:55
0 vmanage dtls 30.255.255.3 250 0 200.250.250.3 12446 200.250.250.3 12446 default up test.com 0:00:25:09
0 vmanage dtls 30.255.255.3 250 0 200.250.250.3 12546 200.250.250.3 12546 default up test.com 0:00:25:56
0 vmanage dtls 30.255.255.3 250 0 200.250.250.3 12646 200.250.250.3 12646 default up test.com 0:00:25:27

vbond# show control connections

vbond# show control local-properties
personality vedge
sp-organization-name test.com
organization-name test.com
root-ca-chain-status Installed
root-ca-crl-status Not-Installed

certificate-status Installed
certificate-validity Valid
certificate-not-valid-before Jan 13 15:26:00 2024 GMT
certificate-not-valid-after Jan 12 15:26:00 2025 GMT

dns-name 200.250.250.21
site-id 250
domain-id 1
protocol dtls
tls-port 0
system-ip 30.255.255.21
chassis-num/unique-id ZZZZZZZZZZZ
serial-num 03
subject-serial-num N/A
token Invalid
keygen-interval 1:00:00:00
retry-interval 0:00:00:16
no-activity-exp-interval 0:00:00:20
dns-cache-ttl 0:00:00:00
port-hopped FALSE
time-since-last-port-hop 0:00:00:00
pairwise-keying Disabled
embargo-check success
cdb-locked false
device-role edge-router
region-id-set N/A
number-vbond-peers 0
number-active-wan-interfaces 1


NAT TYPE: E -- indicates End-point independent mapping
A -- indicates Address-port dependent mapping
N -- indicates Not learned
Note: Requires minimum two vbonds to learn the NAT type

RESTRICT/ LAST VM
PUBLIC PUBLIC PRIVATE PRIVATE PRIVATE MAX CONTROL/ LAST SPI TIME NAT CON REGION
INTERFACE IPv4 PORT IPv4 IPv6 PORT VS/VM COLOR STATE CNTRL STUN LR/LB CONNECTION REMAINING TYPE PRF IDs
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ge0/0 200.250.250.21 12346 200.250.250.21 :: 12346 0/0 default down 2 no/yes/no No/No 0:02:06:05 0:09:53:54 N 5 Default


vbond# show omp peers

vbond# show omp routes
vbond#


****************************************************************************************************************************
****************************************************************************************************************************

 

vSmart01# show control connections
PEER PEER
PEER PEER PEER SITE DOMAIN PEER PRIV PEER PUB
INDEX TYPE PROT SYSTEM IP ID ID PRIVATE IP PORT PUBLIC IP PORT ORGANIZATION REMOTE COLOR STATE UPTIME
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
0 vedge dtls 30.20.20.20 20 1 172.16.22.20 12426 172.16.22.20 12426 test.com mpls up 0:00:48:04
0 vedge dtls 30.20.20.20 20 1 200.10.2.20 12406 200.10.2.20 12406 test.com biz-internet up 0:00:48:03
0 vedge dtls 30.31.31.31 30 1 172.16.31.31 12406 172.16.31.31 12406 test.com default up 0:00:47:17
0 vedge dtls 30.32.32.32 30 1 200.30.1.32 12386 200.30.1.32 12386 test.com default up 0:00:47:59
0 vsmart dtls 30.255.255.12 250 1 200.250.250.12 12346 200.250.250.12 12346 test.com default up 0:00:48:16
0 vsmart dtls 30.255.255.13 250 1 200.250.250.13 12346 200.250.250.13 12346 test.com default up 0:00:48:16
0 vbond dtls 30.255.255.21 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:27:18
0 vmanage dtls 30.255.255.1 250 0 200.250.250.1 12346 200.250.250.1 12346 test.com default up 0:00:47:41
0 vmanage dtls 30.255.255.2 250 0 200.250.250.2 12346 200.250.250.2 12346 test.com default up 0:00:47:43
0 vmanage dtls 30.255.255.3 250 0 200.250.250.3 12346 200.250.250.3 12346 test.com default up 0:00:46:19
1 vbond dtls 30.255.255.21 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:27:23


vSmart01# show control local-properties
personality vsmart
sp-organization-name test.com
organization-name test.com
root-ca-chain-status Installed
root-ca-crl-status Not-Installed

certificate-status Installed
certificate-validity Valid
certificate-not-valid-before Jan 13 15:27:00 2024 GMT
certificate-not-valid-after Jan 12 15:27:00 2025 GMT

dns-name 200.250.250.21
site-id 250
domain-id 1
protocol dtls
tls-port 23456
system-ip 30.255.255.11
chassis-num/unique-id XXXXXXXXXXXX
serial-num 09
subject-serial-num N/A
token -NA-
retry-interval 0:00:00:19
no-activity-exp-interval 0:00:00:20
dns-cache-ttl 0:00:00:00
port-hopped FALSE
time-since-last-port-hop 0:00:00:00
cdb-locked false
region-id-set N/A
number-vbond-peers 1

INDEX IP PORT
-----------------------------------------------------
0 200.250.250.21 12346

number-active-wan-interfaces 2

PUBLIC PUBLIC PRIVATE PRIVATE PRIVATE LAST
INSTANCE INTERFACE IPv4 PORT IPv4 IPv6 PORT VS/VM COLOR STATE CONNECTION
---------------------------------------------------------------------------------------------------------------------------------------------------------------
0 eth0 200.250.250.11 12346 200.250.250.11 :: 12346 2/3 default up 0:00:00:18
1 eth0 200.250.250.11 12446 200.250.250.11 :: 12446 0/0 default up 0:00:00:04


vSmart01# show omp peers
R -> routes received
I -> routes installed
S -> routes sent

DOMAIN OVERLAY SITE
PEER TYPE ID ID ID STATE UPTIME R/I/S
------------------------------------------------------------------------------------------
30.20.20.20 vedge 1 1 20 up 0:01:00:07 4/0/2
30.31.31.31 vedge 1 1 30 up 0:00:59:21 1/0/3
30.32.32.32 vedge 1 1 30 up 0:01:00:04 1/0/3
30.255.255.12 vsmart 1 1 250 up 0:01:00:18 26/0/6
30.255.255.13 vsmart 1 1 250 up 0:01:00:18 20/0/4

vSmart01#


****************************************************************************************************************************
****************************************************************************************************************************

vmanager01# show control connections
PEER PEER PEER
PEER PEER PEER CONFIGURED SITE DOMAIN PEER PRIV PEER PUB
INDEX TYPE PROT SYSTEM IP SYSTEM IP ID ID PRIVATE IP PORT PUBLIC IP PORT ORGANIZATION REMOTE COLOR STATE UPTIME
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
0 vedge dtls 30.32.32.32 30.32.32.32 30 1 200.30.1.32 12386 200.30.1.32 12386 test.com default up 0:00:48:40
0 vsmart dtls 30.255.255.11 30.255.255.11 250 1 200.250.250.11 12346 200.250.250.11 12346 test.com default up 0:00:48:40
0 vsmart dtls 30.255.255.12 30.255.255.12 250 1 200.250.250.12 12346 200.250.250.12 12346 test.com default up 0:00:48:40
0 vsmart dtls 30.255.255.13 30.255.255.13 250 1 200.250.250.13 12346 200.250.250.13 12346 test.com default up 0:00:48:40
0 vbond dtls 30.255.255.21 30.255.255.21 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:27:57
0 vbond dtls 30.255.255.22 30.255.255.22 0 0 200.250.250.22 12346 200.250.250.22 12346 test.com default up 0:02:04:52
0 vbond dtls 30.251.4.4 30.251.4.4 0 0 200.251.4.4 12346 200.251.4.4 12346 test.com default up 0:02:04:36
0 vmanage dtls 30.255.255.2 30.255.255.2 250 0 200.250.250.2 12346 200.250.250.2 12346 test.com default up 0:00:48:56
0 vmanage dtls 30.255.255.3 30.255.255.3 250 0 200.250.250.3 12346 200.250.250.3 12346 test.com default up 0:00:48:55
1 vbond dtls 0.0.0.0 - 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:28:07
1 vbond dtls 0.0.0.0 - 0 0 200.250.250.22 12346 200.250.250.22 12346 test.com default up 0:02:04:52
1 vbond dtls 0.0.0.0 - 0 0 200.251.4.4 12346 200.251.4.4 12346 test.com default up 0:02:04:39
2 vedge dtls 30.20.20.20 30.20.20.20 20 1 200.10.2.20 12406 200.10.2.20 12406 test.com biz-internet up 0:00:49:04
2 vedge dtls 30.31.31.31 30.31.31.31 30 1 172.16.31.31 12406 172.16.31.31 12406 test.com default up 0:00:48:18
2 vedge dtls 40.255.255.40 40.255.255.40 40 1 200.40.1.40 12386 200.40.1.40 12386 test.com biz-internet up 0:00:48:53
2 vedge dtls 30.50.50.92 30.50.50.92 50 1 172.16.52.52 12346 172.16.52.52 12346 test.com mpls up 0:00:49:13
2 vbond dtls 0.0.0.0 - 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:28:04
2 vbond dtls 0.0.0.0 - 0 0 200.250.250.22 12346 200.250.250.22 12346 test.com default up 0:02:04:53
2 vbond dtls 0.0.0.0 - 0 0 200.251.4.4 12346 200.251.4.4 12346 test.com default up 0:02:04:38
3 vbond dtls 0.0.0.0 - 0 0 200.250.250.21 12346 200.250.250.21 12346 test.com default up 0:00:28:05
3 vbond dtls 0.0.0.0 - 0 0 200.250.250.22 12346 200.250.250.22 12346 test.com default up 0:02:04:52
3 vbond dtls 0.0.0.0 - 0 0 200.251.4.4 12346 200.251.4.4 12346 test.com default up 0:02:04:39

vmanager01# show control local-properties
personality vmanage
sp-organization-name test.com
organization-name test.com
root-ca-chain-status Installed
root-ca-crl-status Not-Installed

certificate-status Installed
certificate-validity Valid
certificate-not-valid-before Jan 13 15:26:00 2024 GMT
certificate-not-valid-after Jan 12 15:26:00 2025 GMT

dns-name vbond.test.com
site-id 250
domain-id 0
protocol dtls
tls-port 23456
system-ip 30.255.255.1
chassis-num/unique-id XXXXXXXXXX
serial-num 05
subject-serial-num N/A
cloud-hosted no
token -NA-
retry-interval 0:00:00:16
no-activity-exp-interval 0:00:00:20
dns-cache-ttl 0:00:00:00
port-hopped FALSE
time-since-last-port-hop 0:00:00:00
cdb-locked false
number-vbond-peers 3

INDEX IP PORT
-----------------------------------------------------
0 200.250.250.22 12346
1 200.250.250.21 12346
2 200.251.4.4 12346

number-active-wan-interfaces 4

PUBLIC PUBLIC PRIVATE PRIVATE PRIVATE LAST
INSTANCE INTERFACE IPv4 PORT IPv4 IPv6 PORT VS/VM COLOR STATE CONNECTION
---------------------------------------------------------------------------------------------------------------------------------------------------------------
0 eth0 200.250.250.1 12346 200.250.250.1 :: 12346 3/2 default up 0:00:00:00
1 eth0 200.250.250.1 12446 200.250.250.1 :: 12446 0/0 default up 0:00:00:00
2 eth0 200.250.250.1 12546 200.250.250.1 :: 12546 0/0 default up 0:00:00:00
3 eth0 200.250.250.1 12646 200.250.250.1 :: 12646 0/0 default up 0:00:00:09


****************************************************************************************************************************

uni1389_0-1706634973246.png

uni1389_1-1706635576877.png

 

 

 

Review Cisco Networking for a $25 gift card