cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
1
Replies

SD-WAN connectivity

Juraj Papic
Level 3
Level 3

Hello,

 

I have to migrate routers ISR to the sdwan platform, before I start doing the migration I would like to know what type of connectivity test I can do so I (ping, trace, ) to vmange, vmsart.

 

thanks.

1 Accepted Solution

Accepted Solutions

rbncarvalho
Level 1
Level 1

Hi Juraj, 

 

You can check for ICMP connectivity, but if the controllers are managed by Cisco on AWS they probably will not respond to ICMP.

The one thing you'll need to make sure the devices are able, is to resolve the vBond name, which is the first point of contact for the routers to board the Overlay.

 

Check for the device connectivity to each TLOC gateway, as the device is only able to install the routes if there's connectivity to the next hop. If the next hop is a FW which doesn't respond to ICMP you'll need to disable the track-default-gateway in order for the device install the routes.

 

if the devices are behind a FW you'll need to make sure that the DTLS or TLS ports are open for the IP address of the Controller devices

  • vManage
  • vSmarts
  • vBonds

The FW ports are those in the image below:

viptela_ports.JPG

 

If you can reach the Controllers, resolve the vBond name and those ports are open (if needed) than you should be good to go.


Best Regards, 

Please rate helpful posts

Best Regards,
Please rate helpful posts,

Ruben Carvalho CCIE#57952

View solution in original post

1 Reply 1

rbncarvalho
Level 1
Level 1

Hi Juraj, 

 

You can check for ICMP connectivity, but if the controllers are managed by Cisco on AWS they probably will not respond to ICMP.

The one thing you'll need to make sure the devices are able, is to resolve the vBond name, which is the first point of contact for the routers to board the Overlay.

 

Check for the device connectivity to each TLOC gateway, as the device is only able to install the routes if there's connectivity to the next hop. If the next hop is a FW which doesn't respond to ICMP you'll need to disable the track-default-gateway in order for the device install the routes.

 

if the devices are behind a FW you'll need to make sure that the DTLS or TLS ports are open for the IP address of the Controller devices

  • vManage
  • vSmarts
  • vBonds

The FW ports are those in the image below:

viptela_ports.JPG

 

If you can reach the Controllers, resolve the vBond name and those ports are open (if needed) than you should be good to go.


Best Regards, 

Please rate helpful posts

Best Regards,
Please rate helpful posts,

Ruben Carvalho CCIE#57952
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: