A Comprehensive Guide to SD-WAN Deployment: Migrating from Traditional WAN to Software-Defined WAN

 In today's rapidly evolving technological landscape, organizations are increasingly turning to Software-Defined Wide Area Network (SD-WAN) solutions to enhance their network performance, reduce costs, and streamline operations. This comprehensive guide will walk you through the key steps and considerations involved in migrating from a traditional WAN architecture to SD-WAN, ensuring a smooth and efficient transition.

1. The Importance of Controller Deployment

The first crucial step in any SD-WAN deployment is setting up the controllers. Controllers act as the central management and control plane of the SD-WAN architecture, ensuring seamless communication and coordination across the network.

  • Deployment Sequence: Typically, organizations start by deploying the controllers, followed by the migration of main data centers and hub sites. Finally, remote sites such as campuses and branches are transitioned. This sequence allows hub sites to route traffic between SD-WAN and non-SD-WAN sites during the migration period.

2. Controllers Deployment Options

One of the primary advantages of SD-WAN is the flexibility in controller deployment. Organizations can choose from several options based on their specific needs and compliance requirements:

  • Cisco-Hosted Cloud: The most popular option, with over 90% of customers opting for this model. Cisco handles provisioning, backup, and disaster recovery, offering SD-WAN control plane as a Software-as-a-Service (SaaS).

  • Public Cloud: Organizations can host controllers in public clouds like Azure and AWS, managed either by a service provider or in-house.

  • On-Premises: Suitable for organizations with strict compliance requirements, such as financial and government institutions. In this model, the organization is responsible for backups and disaster recovery.

3. Secure Controller Connections

Once deployed, controllers must establish secure connections. Organizations can choose between Transport Layer Security (TLS) using TCP transport or Datagram Transport Layer Security (DTLS) using UDP transport, with DTLS being the default.

4. WAN Edge Routers Onboarding

The secure onboarding of WAN edge devices is a critical aspect of SD-WAN deployment. Cisco SD-WAN uses a whitelisting model for authenticating and trusting vEdge devices. Each device is uniquely identified by its Chassis ID and certificate serial number.

  • Controllers Reachability: Ensuring WAN edge routers have reachability to all controllers via available transports is vital. This involves establishing control connections over each provisioned transport, starting with the vBond orchestrator.

  • Common Implementations for Controller Reachability:

    • MPLS routed through a data center or regional hub.
    • Public IP addresses of controllers redistributed into the MPLS cloud.
    • Control plane connection through the Internet, although this is not recommended due to lack of redundancy.

5. Joining the Overlay Fabric

The process of joining a WAN edge device to the SD-WAN overlay fabric involves several steps:

  • IP Reachability: The vEdge device obtains an IP address, default gateway, and DNS information via DHCP.
  • Zero-Touch Provisioning: The device reaches the ZTP server to get information about the vBond orchestrator and organization name.
  • Authentication: The device authenticates with its root-certificate and serial number.
  • Connection to Management Plane: The Edge establishes a secure connection to vManage and downloads the configuration.
  • Connection to Control Plane: The device connects to the vSmart controllers and joins the SD-WAN overlay fabric.

6. SD-WAN Operation, Administration, and Management (OAM)

SD-WAN offers significant advantages in terms of operation, administration, and management:

  • Centralized Management: Simplifies operations and reduces change and deployment times.
  • Transport-Independent Overlay: Allows the use of any combination of transports in an active/active fashion, reducing bandwidth costs.
  • Sophisticated Security: Provides comprehensive control plane encryption and a zero-trust security model.
  • Application Visibility: Enables real-time analysis, enforcement of service-level agreements (SLA), and tracking of performance metrics.

Conclusion

Migrating to SD-WAN can transform your network infrastructure, offering enhanced performance, reduced costs, and simplified management. By understanding the key steps and deployment options, you can ensure a successful transition to a modern, software-defined network architecture. Whether you opt for a Cisco-hosted cloud, public cloud, or on-premises deployment, the flexibility and benefits of SD-WAN make it a compelling choice for organizations of all sizes.

 #SDWAN #SDWANDeployment #SoftwareDefinedWAN #Networking #CiscoSDWAN #WANEdgeRouters #NetworkSecurity #CloudNetworking #ITInfrastructure #TechGuide #NetworkingSolutions #Cisco #SDWANMigration #NetworkManagement #DigitalTransformation #TechBlog

ARP & UDP header

 

Acronyms

AH Authentication Header (RFC 2402)

ARP Address Resolution Protocol (RFC 826)

BGP Border Gateway Protocol (RFC 1771)

CWR Congestion Window Reduced (RFC 2481)

DF Do not fragment flag (RFC 791)

DHCP Dynamic Host Configuration Protocol (RFC 2131)

DNS Domain Name System (RFC 1035)

ECN Explicit Congestion Notification (RFC 3168)

ESP Encapsulating Security Payload (RFC 2406)

FTP File Transfer Protocol (RFC 959)

GRE Generic Route Encapsulation (RFC 2784)

HTTP Hypertext Transfer Protocol (RFC 1945)

ICMP Internet Control Message Protocol (RFC 792)

IGMP Internet Group Management Protocol (RFC 2236)

IMAP Internet Message Access Protocol (RFC 2060)

IP Internet Protocol (RFC 791)

ISAKMP Internet Sec. Assoc. & Key Mngm Proto. (RFC 7296)

L2TP Layer 2 Tunneling Protocol (RFC 2661)

OSPF Open Shortest Path First (RFC 1583)

POP3 Post Office Protocol v3 (RFC 1460)

RFC Request for Comments

SMTP Simple Mail Transfer Protocol (RFC 821)

SSH Secure Shell (RFC 4253)

SSL Secure Sockets Layer (RFC 6101)

TCP Transmission Control Protocol (RFC793)

TLS Transport Layer Security (RFC 5246)

TFTP Trivial File Transfer Protocol (RFC 1350)

TOS Type of Service (RFC 2474)

UDP User Datagram Protocol (RFC 768)




UDP Header


UDP Header


Common UDP Ports


7 echo 137 netbios-ns 546 DHCPv6c
19 chargen 138 netbios 547 DHCPv6s
53 domain 161 snmp 1900 SSDP
67 DHCPs 162 snmp-trap 5353 mDNS
68 DHCPc 500 isakmp
69 tftp 514 syslog
123 ntp 520 Rip



Length: number of bytes including UDP header. Minimum value is 8
Checksum includes pseudo-header (IPs, length, protocol), UDP header and payload.


ARP


ARP Header


Hardware Type: 1 - 

Ethernet Protocol Type: 0x0800 - 

IPv4 Address Length: 4=IPv4, 6=Ethernet 

Opcode: 1-request, 2-response





Understanding data analysis

 Understanding data analysis

The 21st century is the century of information. We are living in the age of information,

which means that almost every aspect of our daily life is generating data. Not only this, but

business operations, government operations, and social posts are also generating huge data.

This data is accumulating day by day due to data being continually generated from

business, government, scientific, engineering, health, social, climate, and environmental

activities. In all these domains of decision-making, we need a systematic, generalized,

effective, and flexible system for the analytical and scientific process so that we can gain

insights into the data that is being generated.

In today's smart world, data analysis offers an effective decision-making process for

business and government operations. Data analysis is the activity of inspecting, preprocessing, exploring, describing, and visualizing the given dataset. The main objective of

the data analysis process is to discover the required information for decision-making. Data

analysis offers multiple approaches, tools, and techniques, all of which can be applied to

diverse domains such as business, social science, and fundamental science.

Let's look at some of the core fundamental data analysis libraries of the Python ecosystem:

NumPy: This is a short form of numerical Python. It is the most powerful

scientific library available in Python for handling multidimensional arrays,

matrices, and methods in order to compute mathematics efficiently.

SciPy: This is also a powerful scientific computing library for performing

scientific, mathematical, and engineering operations.

Pandas: This is a data exploration and manipulation library that offers tabular

data structures such as DataFrames and various methods for data analysis and

manipulation.

Scikit-learn: This stands for "Scientific Toolkit for Machine learning". It is a

machine learning library that offers a variety of supervised and unsupervised

algorithms, such as regression, classification, dimensionality reduction, cluster

analysis, and anomaly detection.

Matplotlib: This is a core data visualization library and is the base library for all

other visualization libraries in Python. It offers 2D and 3D plots, graphs, charts,

and figures for data exploration. It runs on top of NumPy and SciPy.

Seaborn: This is based on Matplotlib and offers easy to draw, high-level,

interactive, and more organized plots.

Plotly: Plotly is a data visualization library. It offers high quality and interactive

graphs, such as scatter charts, line charts, bar charts, histograms, boxplots,

heatmaps, and subplots.





The standard process of data analysis

Data analysis refers to investigating the data, finding meaningful insights from it, and

drawing conclusions. The main goal of this process is to collect, filter, clean, transform,

explore, describe, visualize, and communicate the insights from this data to discover

decision-making information. Generally, the data analysis process is comprised of the

following phases:

1. Collecting Data: Collect and gather data from several sources.

2. Preprocessing Data: Filter, clean, and transform the data into the required

format.

3. Analyzing and Finding Insights: Explore, describe, and visualize the data and

find insights and conclusions.

4. Insights Interpretations: Understand the insights and find the impact each

variable has on the system.

5. Storytelling: Communicate your results in the form of a story so that a layman

can understand them.






The KDD process

The KDD acronym stands for knowledge discovery from data or Knowledge Discovery in Databases. Many people treat KDD as one synonym for data mining. Data mining is referred to as the knowledge discovery process of interesting patterns. The main objective of KDD is to extract or discover hidden interesting patterns from large databases, data warehouses, and other web and information repositories. The KDD process has seven major phases:

1. Data Cleaning: In this first phase, data is preprocessed. Here, noise is removed, missing values are handled, and outliers are detected.

2. Data Integration: In this phase, data from different sources is combined and integrated together using data migration and ETL tools.

3. Data Selection: In this phase, relevant data for the analysis task is recollected.
Data Transformation: In this phase, data is engineered in the required appropriate form for analysis.

5. Data Mining: In this phase, data mining techniques are used to discover useful and unknown patterns.

6. Pattern Evaluation: In this phase, the extracted patterns are evaluated.

7. Knowledge Presentation: After pattern evaluation, the extracted knowledge needs to be visualized and presented to business people for decision-making purposes.




SEMMA

The SEMMA acronym's full form is Sample, Explore, Modify, Model, and Assess. This

sequential data mining process is developed by SAS. The SEMMA process has five major

phases:

1. Sample: In this phase, we identify different databases and merge them. After this, we select the data sample that's sufficient for the modeling process.

2. Explore: In this phase, we understand the data, discover the relationships among variables, visualize the data, and get initial interpretations.

3. Modify: In this phase, data is prepared for modeling. This phase involves dealing with missing values, detecting outliers, transforming features, and creating new additional features.

4. Model: In this phase, the main concern is selecting and applying different modeling techniques, such as linear and logistic regression, backpropagation networks, KNN, support vector machines, decision trees, and Random Forest.

5. Assess: In this last phase, the predictive models that have been developed are evaluated using performance evaluation measures

The preceding diagram shows the steps involved in the SEMMA process. SEMMA emphasizes model building and assessment. Now, let's discuss the CRISP-DM process.



CRISP-DM

CRISP-DM's full form is CRoss-InduStry Process for Data Mining. CRISP-DM is a welldefined, well-structured, and well-proven process for machine learning, data mining, and

business intelligence projects. It is a robust, flexible, cyclic, useful, and practical approach to

solving business problems. The process discovers hidden valuable information or patterns

from several databases. The CRISP-DM process has six major phases:

1. Business Understanding: In this first phase, the main objective is to understand

the business scenario and requirements for designing an analytical goal and

initial action plan.

2. Data Understanding: In this phase, the main objective is to understand the data

and its collection process, perform data quality checks, and gain initial insights.

3. Data Preparation: In this phase, the main objective is to prepare analytics-ready

data. This involves handling missing values, outlier detection and handling,

normalizing data, and feature engineering. This phase is the most timeconsuming for data scientists/analysts.

4. Modeling: This is the most exciting phase of the whole process since this is

where you design the model for prediction purposes. First, the analyst needs to

decide on the modeling technique and develop models based on data.

5. Evaluation: Once the model has been developed, it's time to assess and test the

model's performance on validation and test data using model evaluation

measures such as MSE, RMSE, R-Square for regression and accuracy, precision,

recall, and the F1-measure.

6. Deployment: In this final phase, the model that was chosen in the previous step

will be deployed to the production environment. This requires a team effort from

data scientists, software developers, DevOps experts, and business professionals.


The following diagram shows the full cycle of the CRISP-DM process:






The standard process focuses on discovering insights and making interpretations in the
form of a story, while KDD focuses on data-driven pattern discovery and visualizing this.
SEMMA majorly focuses on model building tasks, while CRISP-DM focuses on business
understanding and deployment. Now that we know about some of the processes
surrounding data analysis, let's compare data analysis and data science to find out how
they are related, as well as what makes them different from one other.


Comparing data analysis and data science

Data analysis is the process in which data is explored in order to discover patterns that help
us make business decisions. It is one of the subdomains of data science. Data analysis
methods and tools are widely utilized in several business domains by business analysts,
data scientists, and researchers. Its main objective is to improve productivity and
profits. Data analysis extracts and queries data from different sources, performs exploratory
data analysis, visualizes data, prepares reports, and presents it to the business decisionmaking authorities.
On the other hand, data science is an interdisciplinary area that uses a scientific approach to
extract insights from structured and unstructured data. Data science is a union of all terms,
including data analytics, data mining, machine learning, and other related domains. Data
science is not only limited to exploratory data analysis and is used for developing models
and prediction algorithms such as stock price, weather, disease, fraud forecasts, and
recommendations such as movie, book, and music recommendations.



The roles of data analysts and data scientists

A data analyst collects, filters, processes, and applies the required statistical concepts to capture patterns, trends, and insights from data and prepare reports for making decisions.

The main objective of the data analyst is to help companies solve business problems using discovered patterns and trends. The data analyst also assesses the quality of the data and handles the issues concerning data acquisition. A data analyst should be proficient in writing SQL queries, finding patterns, using visualization tools, and using reporting tools Microsoft Power BI, IBM Cognos, Tableau, QlikView, Oracle BI, and more. Data scientists are more technical and mathematical than data analysts. Data scientists are research- and academic-oriented, whereas data analysts are more application-oriented. Data scientists are expected to predict a future event, whereas data analysts extract significant insights out of data. Data scientists develop their own questions, while data analysts find answers to given questions. Finally, data scientists focus on what is going to happen, whereas data analysts focus on what has happened so far. We can summarize these two roles using the following.


Features Data Scientist Data Analyst
Background Predict future events and scenarios based on data Discover meaningful insights from the data.
Role Formulate questions that can profit the businessSolve the business questions to make decisions.

Type of data Work on both structured and unstructured data Only work on structured data
Programming Advanced programming Basic programming
SkillsetKnowledge of statistics, machine learning algorithms, NLP, and deep learningKnowledge of statistics, SQL, and data visualization
Tools R, Python, SAS, Hadoop, Spark, TensorFlow, and KerasExcel, SQL, R, Tableau, and QlikView


Now that we know what defines a data analyst and data scientist, as well as how they are different from each other, let's have a look at the various skills that you would need to become one of them.




Burp Suite cheat sheet

 Burp Suite cheat sheet

This cheat sheet enables users of Burp Suite with quicker operations and more ease of use.
Burp Suite is the de-facto penetration testing tool for assessing web applications. It enables penetration
testers to rapidly test applications via signature features like repeater, intruder, sequencer, and extender.

Navigational Hotkeys

Ctrl-Shift-T - Target Tab
Ctrl-Shift-P - Proxy Tab
Ctrl-Shift-R - Repeater Tab
Ctrl-Shift-I - Intruder Tab
Ctrl-Shift-O - Project Options Tab
Ctrl-Shift-D - Dashboard Tab
Ctrl-Equal - next tab
Ctrl-Minus - previous tab


Global Hotkeys
Ctrl-I - Send to Intruder
Ctrl-R - Send to Repeater
Ctrl-S - Search (places cursor in search field)
Ctrl-. - Go to next selection
Ctrl-m - Go to previous selection
Ctrl-A - Select all
Ctrl-Z - Undo
Ctrl-Y - Redo



Editor Encoding / Decoding Hotkeys

Ctrl-B - Base64 selection
Ctrl-Shift-B - Base64 decode selection
Ctrl-H - Replace with HTML Entities (key characters only)
Ctrl-Shift-H - Replace HTML entities
with characters
Ctrl-U - URL encode selection (key characters only)
Ctrl-Shift-U - URL decode selection


Editors Hotkeys
Ctrl-Delete - Delete Word
Ctrl-D - Delete Line
Ctrl-Backspace - Delete Word Backwards
Ctrl-Home - Go to beginning of document
Ctrl-Shift-Home - Go to beginning of document and select data on its way
Ctrl-End - Go to end of document
Ctrl-Shift-End - Go to end of document and select data on its way
Ctrl-Left - Go to Previous Word
Ctrl-Shift-Left - Go to Previous Word and select data on its way
Ctrl-Right - Go to Next Word
Ctrl-Shift-Right - Go to Next Word and select data on its way


Burp Collaborator

The collaborator enables the
penetration tester to listen for callbacks from vulnerable scripts and services via auto-generation of unique DNS names and works on the following protocols:
- DNS
- HTTP & HTTPS
- SMTP & SMTPS
Use the Burp extension Taborator to make Burp Collaborator easier to use on-the-fly.



Tool Specific Hotkeys
Ctrl-F – Forward Request (Proxy)
Ctrl-T - Toggle Proxy Intercept On and
Off
Ctrl-Space - Send Request (Repeater)
Double-click <TAB> - Rename a tab


#cybersecurity #burp #cheat #keys #learn

How a Routing Protocol Spans the OSI Model

 

How a Routing Protocol Spans the OSI Model





#osi #layers #physical #protocol #cisco #huawei

What is a Network?

A network is a group of two or more computers or other electronic devices that are interconnected for the purpose of exchanging data and sharing resources through cables, telephone lines, radio waves, satellites, or infrared light beams.


 Types of Network

LAN – Local Area Network
A network contained within one building or over several buildings on a site is called a Local Area Network (LAN).
MAN – Metropolitan Area Network
A network that spans several sites across a city is called a Metropolitan Area Network (MAN).
WAN – Wide Area Network
A network that spans several cities, country or even the world is called a Wide Area Network (WAN).A Client/Server network may be a LAN, MAN or WAN, however a peer-to-peer network can only be a LAN. The most famous and widely used Wide Area Network is the Internet, which contains many thousands of servers and many millions of clients right across the world.


Network Topologies:

A Bus topology consists of a single cable—called a backbone— connecting all nodes on a network without intervening connectivity devices

Devices share responsibility for getting data from one point to another
Terminators stop signals after reaching end of wire
Prevent signal bounce
Inexpensive, not very scalable
Difficult to troubleshoot, not fault-tolerant


Ring topology is a type of network topology in which each device is connected to two other devices on either side via an RJ-45 cable or coaxial cable. 
This forms a circular ring of connected devices which gives it its name. 


Advantages of Ring Topology


Since data flows in one direction, the chance of a packet collision is reduced
A network server is not needed to control network connectivity
Devices can be added without impacting network performance
Easy to identify and isolate single points of failure
Better suited for high traffic environments than a bus topology. 



Disadvantages of Ring Topology

All data travelling over the network must pass through each device on its way to its destination, which can reduce performance
If one device fails, the entire network is impacted
Can be difficult to architect the necessary cabling
More expensive to implement than a bus topology


Bus topology
Bus topology is a specific kind of network topology in which all of the various devices in the network are connected to a single cable or line.


Advantages of Bus Topology

Works efficiently for small networks
Easy and cost-effective to install and add or remove devices
Doesn’t require as much cabling as alternative topologies
If one device fails, other devices are not impacted


Disadvantages of Bus Topology
If the cable is damaged, the entire network will fail or be split
Difficult to troubleshoot problems
Very slow and not ideal for larger networks
Adding more devices and more network traffic decreases the entire network’s performance
Low security due to all devices receiving the same signal from the source


Full Mesh topology
A mesh topology is a network setup where each computer and network device is interconnected with one another. 
This topology setup allows for most transmissions to be distributed even if one of the connections goes down.


Advantages of Mesh Topology

Multiple devices can transmit data at the same time, allowing for high amounts of traffic
If one device fails, data transmission is not impacted in the rest of the network
Adding devices to the network does not disrupt data transmission
Troubleshooting is easier than with alternative topologies


Disadvantages of Mesh Topology

Network installation and maintenance is time and resource intensive
High power requirement due to all the devices needing to remain active all the time
Requires a large amount of cables and ports
The potential for a large amount of redundant connections increases costs and reduces efficiency




Why do we need i-BGP for the routes when we have the IGP protocols (OSPF, IS-IS) for internal communication within the AS?

 Why do we need i-BGP for the routes when we have the IGP protocols (OSPF, IS-IS) for internal communication within the AS?


IGPs like OSPF or ISIS, are link-state protocols that give us all the information of the network and allow for very interesting convergence options and traffic engineering options. Whereas, BGP knows a very limited view of the network as a whole because BGP handles very well filtering and modifying routing information.


See, the traffic in a network can be divided into 4 categories.

• Ingress: traffic arriving from outside the network, destined for hosts within the network.

• Egress: traffic originating inside the network destined for hosts outside the network.

• Internal: traffic where both the origin and destination are within the network.

• Transit: traffic where both the origin and destination are outside the network.


The IGP normally carries internal routes, so it can be used to directly route ingress and internal traffic, but what about egress and transit traffic?


There are three choices -

• Use iBGP

• Use default routes.

• Redistribute external routes into your iGP.


Redistributing the whole internet routing table into your iGP will not end well. iGPs simply are not designed to deal with hundreds of thousands of routes.


If you have only one router that connects to the outside world, then you don't need iBGP. You can simply use a default route to direct egress traffic to your border router. If you have multiple routers that connect to providers then you can still use default routes, but by doing so you lose some of the advantages of multi-homing.


So, we'll be using i-BGP because of Scalability.

Thus, iBGP is required unless you're willing to redistribute all the routes.



#ibgp #bgp #network #cisco #huawei #free #learning

Featured Post

Day 41 — BGP Confederations: Sub-AS Design, External View and Migration

1. Opening Confederations are another way to scale BGP inside a large administrative domain. They divide the domain into member autonomous systems while presenting a single confederation identifier to external peers. They are powerful, but their operational model is more complex than simply 'using private ASNs inside.' The engineering goal is not to memorize another BGP command. It is to understand what information each speaker is allowed to propagate, what path information can be hidden, and what failure domain is created by the chosen control-plane architecture . 2. Concept and standards behavior RFC 5065 defines AS_CONFED_SEQUENCE and AS_CONFED_SET and how member-AS relationships are represented. Confederation external sessions have eBGP-like properties inside the confederation, while the confederation is presented externally as one AS. Modern guidance must also account for the fact that RFC 9774 prohibits new origination of AS_SET/AS_CONFED_SET in ordinary aggregation c...