cisco logo color 2020
8736  Reviews star_rate star_rate star_rate star_rate star_half

Cisco SD-WAN Advanced Policy and Security

Take control of application experience and security at scalemaster advanced Cisco SD WAN policy and SASE integrations in just 3 days. Designed for engineers and architects, this intensive course...

Read More
$3,495 USD
Duration 3 days
Course Code SDWSEC-NTO
Available Formats Classroom, Virtual

Overview

Course Description

Take control of application experience and security at scalemaster advanced Cisco SD WAN policy and SASE integrations in just 3 days. Designed for engineers and architects, this intensive course dives deep into the SD WAN policy framework (centralized/local control & data policies, application aware routing, QoS, segmentation, and security policies, showing you how to harden the edge with SD-WAN integrated security (Firewall, IPS/IDS, Malware Protection and URL filtering). This course also covers the integration between SD-WAN and Cisco Umbrellas full stackDNS Security, Cloud Delivered Firewall, and Secure Internet Gateway. Through step by step design patterns and hands on labs, youll learn how to integrate, operate, and troubleshoot secure Cisco SD WAN across enterprise and service provider environments, enforcing zero trust principles while boosting performance and visibility. By the end, youll be able to build policy with intent, secure users and sites anywhere, and apply best practices that translate directly into reliable, high performing production deployments. The course qualifies for 24 Cisco Continuing Education Credits (CE).

Skills Gained

  • Describe the Cisco SD-WAN architecture, explain its key concepts and identify the control components and their roles
  • Explain the Secure Enterprise Network (SEN) approach with the secure control plane using DTLS tunnels and secure data plabe using IPSec tunnels for a Zero trust networking
  • Define Direct Internet Access (DIA) at branch locations in the SD-WAN infrastructure and identify the security challenges associated to it
  • List the network security considerations when migrating enterprise applications and services to public cloud and summarize what is Cloud on Ramp and how it addresses security concerns in the context of SaaS and IaaS
  • List the multiple security mechanisms included in the SD-WAN integrated security approach, including Zone Based Firewall, Intrusion Detection and Prevention, Advanced Malware Protection and URL filtering, and the uses cases and scenarios where they are applied
  • Design and deploy security policies with integrated services in SD-WAN infrastructures using SD-WAN Manager workflows
  • Identify the security risks involved with the domain name resolution services (DNS) and what are the strategies to shield the DNS lookups
  • Design, implement, verify, operate and support DNA security using Cisco Umbrella
  • Describe the Secure Internet Gateway (SIG) approach to deploy security into SD-WAN solutions as a Cloud-based service and match the benefits of Cisco Umbrella as SIG solution
  • Integrate SD-WAN with Cisco Umbrella for Cloud Firewall services
  • Troubleshoot SD-WAN and Cisco Umbrella Integration, diagnosing and solving integration and security policy issues

Who Can Benefit

The primary audience for this course is as follows:

  • Systems Engineers
  • Technical Solutions Architects
  • Field Engineers

Prerequisites

The knowledge and skills that the learner should have before attending this course are as follows:

  • Knowledge of WAN architectures and routing networking concepts
  • High-level familiarity with basic network protocols and applications
  • Familiarity with common application delivery methods
  • Fundamental Understanding of perimeter security
  • Basic Cisco SD-WAN familiarity
|
View Full Schedule

Course Details

Course Details

Course Outline: Module 1: Cisco SD-WAN Introduction

  • High-level Cisco SD-WAN Deployment models
  • Application-level SD-WAN solution
  • Cisco SDWAN plan for HA and Scalability
  • Cisco SD-WAN solution components: vManage NMS, vSmart Controller, vBond Orchestrator
  • Edge Routers (cEdge, vEdge, and Catalyst 8K)
  • Cloud Based Deployment vs On-Premises Deployment

Module 2: Zero Touch Provisioning

  • Overview
  • User Input Required for the ZTP Automatic Authentication Process
  • Authentication between the vBond Orchestrator and WAN Edges
  • Authentication between the Edge Routers and the vManage NMS
  • Authentication between the vSmart Controller and the Edge Routers

Module 3: Cisco SD-WAN Solution

  • Overlay Management Protocol (OMP)
  • Cisco SD-WAN Circuit Aggregation Capabilities
  • Secure Connectivity in Cisco SD-WAN
  • Performance Tracking Mechanisms
  • Application Discovery
  • Dynamic Path Selection
  • Performance Based Routing
  • Direct Internet Access
  • Advanced Routing (OSPF, BGP, LISP, VXLAN, MPLS)
  • Application Aware Routing
  • Localized and Centralized Policies (Data and Control)
  • Cisco SD-WAN In-built Security features: App Aware FW, Talos IPS, URL Filtering, Umbrella Integration, and Advanced Malware Protection
  • Dynamic Cloud Access: Cloud On-Ramp for SaaS and IaaS (AWS, Azure & GPC)
  • API and Programmatic Interaction via Python

Module 4: Deeper Insight into Cisco SD-WAN Security

  • Designing Security Requirements within Cisco SD-WANDIA SecurityDirect Cloud Access SecurityGuest User SecurityCompliance Requirements
  • Security Implementation at the Branch Site
  • Implementing Zone Based Firewalls on Cisco WAN Edge
  • Implementing UTD on Cisco WAN EdgeConfiguring URL FilteringConfiguring Snort IPSBest Practices for UTD setup (Based on production deployment experiences)
  • Implementing Advanced Malware ProtectionConfiguring AMPOverview of integration with Threat Grid

Module 5: Designing and Implementing DNS Security

  • Prerequisite check before integrating Umbrella with Cisco SD-WANMaking sure you have the correct licensingPlatform support checkInternet Connectivity check
  • Walking through the Umbrella DashboardDashboard OverviewDNS Policy GUI OverviewFirewall Policy GUI OverviewWeb Policy GUI OverviewUmbrella AD/SAML Integration Overview (optional)
  • Integrating Cisco Umbrella for DNS SecurityUmbrella API Integration
  • Configuring the DNS Encryption PolicyExcluding the local domainsConfiguring the Security Policy in vManageImplementing the policy at the DIA Sites
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 6: Cisco SD-WAN and Cisco Umbrella SIG Integration

  • SIG Integration Overview
  • Configuring Cisco vManage Templates for SIG Tunnel CreationUsing the pre-configured Feature Templates in vManage 20.X
  • Adding the SD-WAN Routers and Sites in Umbrella IdentitiesValidate that the routers show up from the Umbrella Dashboard
  • Designing and Configuring Policy for SIG RedirectionSetting up the vSmart Centralized Policies for SIG Redirection on DIA Traffic
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 7: Cisco SD-WAN and Cisco Umbrella Cloud Firewall Integration

  • Umbrella Cloud Firewall Integration Overview
  • Configuring Cisco vManage Templates for Firewall Tunnel CreationUsing the pre-configured Feature Templates in vManage 20.X
  • Adding the SD-WAN Routers and Sites in Umbrella IdentitiesValidate that the routers show up from the Umbrella Dashboard
  • Designing and Configuring Policy for Firewall RedirectionSetting up the vSmart Centralized Policies for Umbrella FW Redirection on DIA Traffic
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 8: Troubleshooting Umbrella Integration

  • Troubleshooting DNS SecurityAPI Integration not workingDNS for local domain failingNo redirection to Cisco Umbrella for external domains
  • Troubleshooting SIG and FirewallMaking sure the IPSec Tunnels to Troubleshooting the vManage policies for redirectionLoad balancing using vManage policiesReviewing logs in Umbrella
  • Checking Alarms and NotificationsChecking Alarms on vManageChecking Alarms on Cisco Umbrella

Lab Outline: Labs are designed to assure learners a whole practical experience, through the following practical activities:

  • Onboard Edge
  • Onboard Edge via ZTP
  • Onboard vSmart Controller
  • AVC integration and Traffic Visibility
  • Application Aware Routing Lab
  • Local DIA and Regional DIA
  • Backup and Restore using Python API
  • Intra Zone Firewall
  • Inter Zone Firewall
  • UTD integrationURL FilteringSnort IPS
  • Umbrella IntegrationDNS PolicyWeb Policy
  • SIG Tunnel Creation
  • SIG Tunnel Redirection Policy
  • Configuring Policy for Umbrella Firewall Redirection
  • Trouble Ticket 1
  • Trouble Ticket 2
  • Trouble Ticket 3

Schedule

3 options available

  • Jun 15, 2026 - Jun 17, 2026 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 option(s) below
    Virtual | 10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Aug 10, 2026 - Aug 12, 2026 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 option(s) below
    Virtual | 10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Oct 13, 2026 - Oct 15, 2026 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 option(s) below
    Virtual | 10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote

FAQ

Does the course schedule include a Lunchbreak?

Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does Ascendient Learning deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

What does vendor-authorized training mean?

As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.

Is the training too basic, or will you go deep into technology?

It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.

How up-to-date are your courses and support materials?

We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.

Are your instructors seasoned trainers who have deep knowledge of the training topic?

Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.

Do you provide hands-on training and exercises in an actual lab environment?

Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.

Will you customize the training for our company’s specific needs and goals?

We will work with you to identify training needs and areas of growth.  We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.

How do I get started with certification?

Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.

Will I get access to content after I complete a course?

You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.

How do I request a W9 for Ascendient Learning?

View our filing status and how to request a W9.

Reviews

Sean is the very good instructor. I would like to take his class again in the future.

Brandon was a great instructor. The virtual course materials and labs provided were very informative.

This is my second course with ExitCertified. This course exceeded my expectations. The teacher was great and the class was fun.

Very good material, the instructor was clear explaining the topics, and the labs were easy to follow it.

This was a good program to get prepared for the solutions architect associate exam.