KL 004.2.4: Kaspersky SD-WAN

Categories: Kaspersky

About Course

Course description

Kaspersky SD-WAN is an enterprise solution designed for centralized management of wide area networks (WAN). This course provides participants with an understanding of the Kaspersky SD-WAN architecture, key capabilities, configuration methods, and troubleshooting techniques. It combines theoretical concepts with hands-on labs to develop practical skills in deploying and managing SD-WAN environments.

Upon successful completion of this course, participants will be able to:

  • Understand the benefits of software-defined WANs compared to traditional networks.
  • Understand the characteristics and use cases of different transport services.
  • Create, configure, and manage transport services.
  • Configure channel selection rules based on the current status of available channels.
  • Manage dynamic routing within an SD-WAN network and its integration with legacy networks.

Chapter 1. Introduction

1.1. Traditional WANs and Their Problems
1.2. What Is Expected from SD-WAN: Research by Pulse and Telstra
1.3. Conclusion
1.4. Industries
1.5. What Is an SD-WAN?
1.6. Components of the Kaspersky SD-WAN Solution
1.7. Use Cases

Chapter 2. Functionality

2.1. Centralized Management
2.2. Traffic Balancing
2.3. Failover
2.4. Forward Error Correction
2.5. Packet Duplication
2.6. Quality Assurance
2.7. ZTP
2.8. CFM
2.9. DHCP
2.10. Rollback to a Known Good Configuration
2.11. High-Availability (HA) Pair
2.12. Component Fault Tolerance

Chapter 3. Architectural Solutions

3.1. Transport Services
3.2. Service Interfaces
3.3. Use of Multiple L2 Services
3.4. L3 with Dynamic Routing
3.5. L3 Multi-Vendor
3.6. Example with iBGP RR in an Overlay
3.7. Tags
3.8. Virtual Routing and Forwarding (VRF)
3.9. Internal Architecture of CPE and uCPE

Chapter 4. Security

4.1. TLS, DTLS, HTTPS
4.2. PSK
4.3. Two-Factor Authentication (2FA)
4.4. LDAP
4.5. Encryption

Chapter 5. Monitoring and Control

5.1. Zabbix
5.2. NTP
5.3. Management

Chapter 6. Deployment

6.1. Solution Components
6.2. Configuration Plan
6.3. SD-WAN Installation
6.4. Configuring SD-WAN via the Web Interface
6.5. Deployment of the SD-WAN Service
6.6. CPE Deployment

Chapter 7. Troubleshooting

7.1. Health Check of Central Components of the Solution
7.2. Health Check of the Controller Cluster
7.3. Checking Configuration of CPE and GW
7.4. Verification of Network Connectivity Between CPE, GW, and Central Components of the Solution

Chapter 8. Technical Specification

8.1. Resources
8.2. CPE Models
8.3. Licensing

Labs

Lab 1. Install and Configure an SD-WAN Server and Perform Initial Configuration of the Solution

1.1. Turn On Servers and Virtual Machines
1.2. Install Packages and Set Environment Variables on the Server
1.3. Start SD-WAN Installation Using an Ansible Playbook
1.4. Open the Kaspersky SD-WAN Management Console and Configure the Environment
1.5. Create a New Tenant

Lab 2. Create a Physical Network Function Template and Deploy the SD-WAN Service

2.1. Upload the SD-WAN Physical Network Function Template
2.2. Create an SD-WAN Service Template and Deploy the SD-WAN Service

Lab 3. Prepare Templates of Client Network Devices and Connect Them to the Kaspersky SD-WAN Service

3.1. Upload the Root Certificate to Kaspersky SD-WAN
3.2. Prepare and Upload the Gateway Template
3.3. Register the Gateway with Kaspersky SD-WAN
3.4. Prepare and Upload Templates of Client Network Devices
3.5. Register CPE1
3.6. Prepare and Import the CPE2_1 and CPE2_2 Templates

Lab 4. Configure Point-to-Multipoint (P2M) and Multipoint-to-Multipoint (M2M) Services

4.1. Configure a Point-to-Multipoint Service and Check Its Health
4.2. Configure a Multipoint-to-Multipoint Service and Check Its Health
4.3. Configure CPE Time Synchronization Using NTP
4.4. Configure Dynamic Routing via BGP in the WAN Segment
4.5. Speed Up Connectivity Loss Detection

Lab 5. Configure Connection with Legacy Networks

5.1. Simulate a Non-Redundant L3 Connection with BGP Dynamic Routing
5.2. Configure Dynamic Allocation of IP Addresses Using DHCP
5.3. Simulate an L3 Connection with Default Gateway Redundancy Using VRRP
5.4. Simulate a Redundant L3 Connection with Dynamic Routing Using OSPF

Lab 6. Test Backup and Automatic Channel Failover

 

Lab 7. Enable Connection Quality Monitoring and Check Channel Failover When Thresholds Are Exceeded

 

Lab 8. Enable and Test Forward Error Correction

 

Lab 9. Configure Traffic Management Based on DPI

9.1. Specify the “Last Resort” Setting for the Links
9.2. Enable DPI in the Firewall CPE Template
9.3. Create a Rule to Classify SSH Test Traffic
9.4. Create ACL Service Interfaces
9.5. Create a Dedicated Transport Service for Priority Traffic

Lab 10. Migrate Client Networks to Dedicated VRFs on CPE Devices

10.1. Configure VRF on GW and CPE1 via the Orchestrator
10.2. View Settings via the CPE1 Console

Lab 11. Configure PBR Between VRFs to Organize Local Breakout

11.1. Configure PBR on CPE1
11.2. Add a Default Route to BGP on CPE1

Lab 12. Use REST API to Create a New Tenant and Tenant Administrator

World Food Programme (WFP)

Our work with the World Food Programme (WFP) focused on enabling the effective adoption of digital field technologies and essential digital literacy capabilities. Participants utilized mobile-based data collection platforms within operational contexts, enhancing accuracy, consistency, and confidence in digital data handling. The engagement strengthened WFP’s ability to rely on digital tools to support field operations and humanitarian programs.

Raya

For Raya, we delivered technology enablement focused on automation-driven operations and scalable application development. Participants gained hands-on experience with automation technologies and modern front-end development frameworks, supporting more efficient processes and the delivery of flexible, high-performance digital solutions aligned with business growth objectives.

EgyptAir

Our engagement with EgyptAir focused on enabling the effective use of application development technologies alongside the adoption of cybersecurity and secure computing practices within operational environments. Participants worked with Microsoft-based development platforms and programming technologies while gaining practical exposure to secure application usage, access control mechanisms, and threat-aware system interaction. This integrated technology enablement supported more secure digital operations, improved system reliability, and reinforced cyber resilience across aviation technology environments.

Banque Misr

We collaborated with Banque Misr to enable integrated enterprise technology capabilities across multiple domains. The engagement supported effective utilization of IT infrastructure environments, data analytics platforms, and professional capability development frameworks, allowing teams to operate confidently within complex enterprise systems. Our delivery approach focused on practical technology adoption, operational alignment, and building sustainable competencies that support reliable banking services and informed, data-driven decision-making.

Course Booking Form