Edge Routers authenticate via vBond; form secure DTLS control sessions with vSmart using Overlay Management Protocol (OMP)
Status: Step 1 -> WAN Edge (vedge1) initiates Zero-Touch Authentication to vBond Orchestrator.
Cisco SD-WAN CLI Console - Edge-1 (cEdge/vEdge)
Edge-1# show control connections
Edge-1#
What is Software-Defined WAN (SD-WAN)?
Cisco SD-WAN (Viptela Architecture) separates the control plane from the data plane, creating a secure, transport-independent overlay network over any combination of transport links (MPLS, Broadband Internet, 4G/5G LTE).
The 4 Pillars / Planes of SD-WAN Architecture
Orchestration Plane (vBond): The initial rendezvous point. Authenticates controllers/edges using TPM/certs and orchestrates NAT traversal.
Control Plane (vSmart): The central brain. Uses OMP (Overlay Management Protocol) to distribute routing, TLOC keys, and policy rules across all WAN Edges.
Management Plane (vManage): Single pane of glass GUI for centralized configuration, zero-touch provisioning (ZTP), monitoring, and troubleshooting.
Data Plane (WAN Edge / vEdge / cEdge): Physical/virtual routers at branches, data centers, or clouds. Securely forwards data traffic using auto-created IPsec tunnels monitored by BFD.
Key SD-WAN Concepts
TLOC (Transport Location): Identifies a WAN Edge interface attachment point (System-IP, Color, Encapsulation).
OMP (Overlay Management Protocol): TCP-based protocol (Port 12346) running over TLS/DTLS tunnels between vSmart and Edges.
BFD (Bidirectional Forwarding Detection): Continuously measures latency, jitter, loss, and path availability across dynamic IPsec tunnels.