09-22-2019 04:55 PM
Hello,
I have to migrate routers ISR to the sdwan platform, before I start doing the migration I would like to know what type of connectivity test I can do so I (ping, trace, ) to vmange, vmsart.
thanks.
Solved! Go to Solution.
09-23-2019 08:23 AM - edited 09-23-2019 08:33 AM
Hi Juraj,
You can check for ICMP connectivity, but if the controllers are managed by Cisco on AWS they probably will not respond to ICMP.
The one thing you'll need to make sure the devices are able, is to resolve the vBond name, which is the first point of contact for the routers to board the Overlay.
Check for the device connectivity to each TLOC gateway, as the device is only able to install the routes if there's connectivity to the next hop. If the next hop is a FW which doesn't respond to ICMP you'll need to disable the track-default-gateway in order for the device install the routes.
if the devices are behind a FW you'll need to make sure that the DTLS or TLS ports are open for the IP address of the Controller devices
The FW ports are those in the image below:
If you can reach the Controllers, resolve the vBond name and those ports are open (if needed) than you should be good to go.
Best Regards,
Please rate helpful posts
09-23-2019 08:23 AM - edited 09-23-2019 08:33 AM
Hi Juraj,
You can check for ICMP connectivity, but if the controllers are managed by Cisco on AWS they probably will not respond to ICMP.
The one thing you'll need to make sure the devices are able, is to resolve the vBond name, which is the first point of contact for the routers to board the Overlay.
Check for the device connectivity to each TLOC gateway, as the device is only able to install the routes if there's connectivity to the next hop. If the next hop is a FW which doesn't respond to ICMP you'll need to disable the track-default-gateway in order for the device install the routes.
if the devices are behind a FW you'll need to make sure that the DTLS or TLS ports are open for the IP address of the Controller devices
The FW ports are those in the image below:
If you can reach the Controllers, resolve the vBond name and those ports are open (if needed) than you should be good to go.
Best Regards,
Please rate helpful posts
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: