Document
Cisco SD-WAN Virtual Private Networks (VPNs)

Cisco SD-WAN Virtual Private Networks (VPNs)

Virtual Private Networks (VPNs) are used for segmentation in the SD-WAN overlay, same as VRF, which we are familiar with. Each VPN is having its own f

Related articles

What is OpenVPN? Understanding Secure Networking 1.2: Atomic Structure Surfshark Antivirus Review: Should You Get It in 2024? Novel attack against virtually all VPN apps neuters their entire purpose Working with apps

Virtual Private Networks (VPNs) are used for segmentation in the SD-WAN overlay, same as VRF, which we are familiar with. Each VPN is having its own forwarding table and is separated from each other. An interface or subinterface can be included and become a part of one VPN only. The VPN a packet belongs to is identified by the labels in OMP route attributes and in the packet encapsulation.

 

The VPN number is a four-byte integer and the range is 0- 65535, maximum of 65527 VPN can be configured as several VPNs are reserved for internal use. The default VPN available in the WAN Edge devices and controllers are VPN 0 and VPN 512. These 2 VPN (VPN 0 and 512) need to be configured on vManage and vSmart controllers. For the vBond orchestrator, only VPN 0 and 512 are functional and the only ones thatthat are used. 

 

Transport VPN (VPN 0) – This VPN contains those interfaces, which are used to connect to the transports. Secure DTLS/ TLS connections to the controllers are established from this VPN. Static/ Default/ Dynamic routing protocols are configured inside this VPN to get the correct next-hop information in order to establish the control plane and IPsec tunnel that can reach the remote sites. 

management VPN ( VPN 512 ) – This VPN is used to carry the out – of – band management traffic to and from the SD – WAN device . OMP is ignores ignore this VPN and is not carry across the overlay network .  

service – side VPN ( VPN 1 – 511 and 513 – 65527 ) – This VPN is includes include the interface used to carry user datum traffic to the local – site network . service vpn can be configure with OSPF or BGP , Virtual Router redundancy Protocol ( VRRP ) , qos , etc . User traffic isis is carried carry over the IPsec tunnel to other remote site by redistribute OMP route receive from the vSmart controller into the service – side VPN routing protocol . We is need need to advertise the Service VPN route into OMP routing protocol so that route from the local site can be advertise to other site , which is send to the vSmart controller and then redistribute to the other WAN Edge router .