Tagged: SDWSCS
13 posts · browse all tags
-
SDWSCS Part 13: Monitoring with vManage & vAnalytics
The SDWSCS finale — module 13: operating everything the series deployed. vManage's security and Cloud OnRamp dashboards, the UTD and tunnel health signals worth alerting on, vAnalytics/Cisco SDWAN Analytics for trends and forecasting, and a day-2 runbook.
-
SDWSCS Part 12: Cloud Interconnect & OnRamp for Colocation
Modules 11–12 of SDWSCS: software-defined cloud interconnect with Megaport and Equinix — virtual routers and private cross-connects provisioned from vManage — and Cloud OnRamp for Colocation: CSP clusters, NFVIS, and vManage-orchestrated VNF service chains.
-
SDWSCS Part 11: Cloud OnRamp Multicloud — AWS, Azure & GCP
Module 10 of SDWSCS: extending the fabric into public cloud with Cloud OnRamp for Multicloud — cloud gateways built from Catalyst 8000Vs, AWS Transit Gateway and Cloud WAN, Azure vWAN, GCP NCC, and the tag-based intent mapping that connects VPCs to service VPNs.
-
SDWSCS Part 10: Cloud OnRamp for SaaS
Module 9 of SDWSCS: Cloud OnRamp for SaaS in deployment detail — vQoE probing and scoring, DIA vs gateway vs client access exits, the Microsoft 365 telemetry integration, Webex/Office/custom app lists, and verifying the path decisions it makes.
-
SDWSCS Part 9: ThousandEyes — Monitoring Cloud Services
Module 8 of SDWSCS: deploying ThousandEyes enterprise agents in app hosting on Catalyst edges, test types and what each proves, the vManage integration, and building Microsoft 365 monitoring that turns 'Teams is slow' into an actionable path diagnosis.
-
SDWSCS Part 8: CASB, DLP & Securing Microsoft 365
Module 7 of SDWSCS: the CASB layer riding on Umbrella SIG — shadow IT discovery, app controls, tenant restrictions for Microsoft 365, data loss prevention, and remote browser isolation. What each control needs from the SDWAN side to work.
-
SDWSCS Part 7: Umbrella SIG — Deployment & DNS Policies
Module 6 of SDWSCS: Umbrella SIG architecture and deployment — the automatic tunnel workflow from vManage, active/active vs active/backup designs, steering traffic into the SIG, and DNS security policies as the first (and cheapest) enforcement layer.
-
SDWSCS Part 6: SASE — Architecture & Use Cases
Module 5 of SDWSCS: what SASE actually is once the marketing is stripped away — the SSE service stack, how Cisco assembles it from Catalyst SDWAN, Umbrella, Duo and ThousandEyes, and the use cases where cloud-delivered enforcement beats on-box or chained designs.
-
SDWSCS Part 5: Secure DIA & Service Chaining
Module 4 of SDWSCS: assembling the embedded stack into a secure Direct Internet Access design, then service chaining — OMP service routes, control and data policy steering, and the dedicated-security patterns for traffic that must transit a real firewall.
-
SDWSCS Part 4: Content Filtering — URL Filtering & TLS/SSL Decryption
Module 3 of SDWSCS: URL filtering with categories and web reputation, block pages, and the TLS/SSL decryption proxy — CA design choices, the decrypt policy, undecryptable traffic handling, and why decryption is the feature that needs a change-management plan.
-
SDWSCS Part 3: On-Premises Threat Prevention — Firewall, IPS & AMP
Module 2 of SDWSCS: deploying the application-aware enterprise firewall, Snort-based IPS with its three signature sets, and AMP file reputation with Threat Grid sandboxing — plus fail-open vs fail-close and the verification commands for each.
-
SDWSCS Part 2: The SDWAN Security Model & Unified Security Policy
Module 1 of the SDWSCS syllabus: why DIA changed the threat model, the four security deployment patterns, what actually runs on a Catalyst edge (zone-based firewall vs the UTD container), and the unified security policy framework that ties it together.
-
SDWSCS Part 1: Course Overview & Study Roadmap
Kicking off a thirteen-part series on Cisco's SDWSCS syllabus — SDWAN security and cloud solutions. Part 1 explains what the course covers, how it extends ENSDWI, maps all thirteen modules and eleven labs to this series, and sets out a realistic study plan.