About Course
Course description
Kaspersky SD-WAN is an enterprise solution designed for centralized management of wide area networks (WAN). This course provides participants with an understanding of the Kaspersky SD-WAN architecture, key capabilities, configuration methods, and troubleshooting techniques. It combines theoretical concepts with hands-on labs to develop practical skills in deploying and managing SD-WAN environments.
Upon successful completion of this course, participants will be able to:
- Understand the benefits of software-defined WANs compared to traditional networks.
- Understand the characteristics and use cases of different transport services.
- Create, configure, and manage transport services.
- Configure channel selection rules based on the current status of available channels.
- Manage dynamic routing within an SD-WAN network and its integration with legacy networks.
Chapter 1. Introduction
1.1. Traditional WANs and Their Problems
1.2. What Is Expected from SD-WAN: Research by Pulse and Telstra
1.3. Conclusion
1.4. Industries
1.5. What Is an SD-WAN?
1.6. Components of the Kaspersky SD-WAN Solution
1.7. Use Cases
Chapter 2. Functionality
2.1. Centralized Management
2.2. Traffic Balancing
2.3. Failover
2.4. Forward Error Correction
2.5. Packet Duplication
2.6. Quality Assurance
2.7. ZTP
2.8. CFM
2.9. DHCP
2.10. Rollback to a Known Good Configuration
2.11. High-Availability (HA) Pair
2.12. Component Fault Tolerance
Chapter 3. Architectural Solutions
3.1. Transport Services
3.2. Service Interfaces
3.3. Use of Multiple L2 Services
3.4. L3 with Dynamic Routing
3.5. L3 Multi-Vendor
3.6. Example with iBGP RR in an Overlay
3.7. Tags
3.8. Virtual Routing and Forwarding (VRF)
3.9. Internal Architecture of CPE and uCPE
Chapter 4. Security
4.1. TLS, DTLS, HTTPS
4.2. PSK
4.3. Two-Factor Authentication (2FA)
4.4. LDAP
4.5. Encryption
Chapter 5. Monitoring and Control
5.1. Zabbix
5.2. NTP
5.3. Management
Chapter 6. Deployment
6.1. Solution Components
6.2. Configuration Plan
6.3. SD-WAN Installation
6.4. Configuring SD-WAN via the Web Interface
6.5. Deployment of the SD-WAN Service
6.6. CPE Deployment
Chapter 7. Troubleshooting
7.1. Health Check of Central Components of the Solution
7.2. Health Check of the Controller Cluster
7.3. Checking Configuration of CPE and GW
7.4. Verification of Network Connectivity Between CPE, GW, and Central Components of the Solution
Chapter 8. Technical Specification
8.1. Resources
8.2. CPE Models
8.3. Licensing
Labs
Lab 1. Install and Configure an SD-WAN Server and Perform Initial Configuration of the Solution
1.1. Turn On Servers and Virtual Machines
1.2. Install Packages and Set Environment Variables on the Server
1.3. Start SD-WAN Installation Using an Ansible Playbook
1.4. Open the Kaspersky SD-WAN Management Console and Configure the Environment
1.5. Create a New Tenant
Lab 2. Create a Physical Network Function Template and Deploy the SD-WAN Service
2.1. Upload the SD-WAN Physical Network Function Template
2.2. Create an SD-WAN Service Template and Deploy the SD-WAN Service
Lab 3. Prepare Templates of Client Network Devices and Connect Them to the Kaspersky SD-WAN Service
3.1. Upload the Root Certificate to Kaspersky SD-WAN
3.2. Prepare and Upload the Gateway Template
3.3. Register the Gateway with Kaspersky SD-WAN
3.4. Prepare and Upload Templates of Client Network Devices
3.5. Register CPE1
3.6. Prepare and Import the CPE2_1 and CPE2_2 Templates
Lab 4. Configure Point-to-Multipoint (P2M) and Multipoint-to-Multipoint (M2M) Services
4.1. Configure a Point-to-Multipoint Service and Check Its Health
4.2. Configure a Multipoint-to-Multipoint Service and Check Its Health
4.3. Configure CPE Time Synchronization Using NTP
4.4. Configure Dynamic Routing via BGP in the WAN Segment
4.5. Speed Up Connectivity Loss Detection
Lab 5. Configure Connection with Legacy Networks
5.1. Simulate a Non-Redundant L3 Connection with BGP Dynamic Routing
5.2. Configure Dynamic Allocation of IP Addresses Using DHCP
5.3. Simulate an L3 Connection with Default Gateway Redundancy Using VRRP
5.4. Simulate a Redundant L3 Connection with Dynamic Routing Using OSPF
Lab 6. Test Backup and Automatic Channel Failover
Lab 7. Enable Connection Quality Monitoring and Check Channel Failover When Thresholds Are Exceeded
Lab 8. Enable and Test Forward Error Correction
Lab 9. Configure Traffic Management Based on DPI
9.1. Specify the “Last Resort” Setting for the Links
9.2. Enable DPI in the Firewall CPE Template
9.3. Create a Rule to Classify SSH Test Traffic
9.4. Create ACL Service Interfaces
9.5. Create a Dedicated Transport Service for Priority Traffic
Lab 10. Migrate Client Networks to Dedicated VRFs on CPE Devices
10.1. Configure VRF on GW and CPE1 via the Orchestrator
10.2. View Settings via the CPE1 Console
Lab 11. Configure PBR Between VRFs to Organize Local Breakout
11.1. Configure PBR on CPE1
11.2. Add a Default Route to BGP on CPE1