cisco logo color 2020
8280  Reviews star_rate star_rate star_rate star_rate star_half

Cisco SD-WAN Advanced Policy and Security

SDWSECis a Cisco SASE (Secure Access Service Edge) training targeted to engineers and technical personnel involved in designing, deploying, operating, and securing Cisco Edge solutions both in...

Read More
$3,495 USD
Duration 3 days
Course Code SDWSEC-NTO
Available Formats Classroom, Virtual

Overview

SDWSECis a Cisco SASE (Secure Access Service Edge) training targeted to engineers and technical personnel involved in designing, deploying, operating, and securing Cisco Edge solutions both in enterprise and Service Provider environments. This training is specifically designed for partners and customers implementing secure Cisco SD-WAN integrated with the complete feature set of Cisco Umbrella including DNS Security, Cloud Based Firewall and Secure Internet Gateway. The course walks you through how each integration works and how to design and implement it step-by-step. The course qualifies for 24 Cisco Continuing Education Credits (CE).

Skills Gained

Upon completing this course, you will be able to meet the following objectives:

  • Describe SD-WAN Architecture
  • Design Cisco SD-WAN Branch Security
  • Implement Cisco SD-WAN Secure Internet and Cloud Access
  • Integrate and Troubleshoot Cisco SD-WAN with a SASE Solution

Who Can Benefit

The primary audience for this course is as follows:

  • Systems Engineers
  • Technical Solutions Architects
  • Field Engineers

Prerequisites

The knowledge and skills that the learner should have before attending this course are as follows:

  • Knowledge of WAN architectures and routing networking concepts
  • High-level familiarity with basic network protocols and applications
  • Familiarity with common application delivery methods
  • Fundamental Understanding of perimeter security
  • Basic Cisco SD-WAN familiarity

Course Details

Module 1: Cisco SD-WAN Introduction

  • High-level Cisco SD-WAN Deployment models
  • Application-level SD-WAN solution
  • Cisco SDWAN plan for HA and Scalability
  • Cisco SD-WAN solution components: vManage NMS, vSmart Controller, vBond Orchestrator
  • Edge Routers (cEdge, vEdge, and Catalyst 8K)
  • Cloud Based Deployment vs On-Premises Deployment

Module 2: Zero Touch Provisioning

  • Overview
  • User Input Required for the ZTP Automatic Authentication Process
  • Authentication between the vBond Orchestrator and WAN Edges
  • Authentication between the Edge Routers and the vManage NMS
  • Authentication between the vSmart Controller and the Edge Routers

Module 3: Cisco SD-WAN Solution

  • Overlay Management Protocol (OMP)
  • Cisco SD-WAN Circuit Aggregation Capabilities
  • Secure Connectivity in Cisco SD-WAN
  • Performance Tracking Mechanisms
  • Application Discovery
  • Dynamic Path Selection
  • Performance Based Routing
  • Direct Internet Access
  • Advanced Routing (OSPF, BGP, LISP, VXLAN, MPLS)
  • Application Aware Routing
  • Localized and Centralized Policies (Data and Control)
  • Cisco SD-WAN In-built Security features: App Aware FW, Talos IPS, URL Filtering, Umbrella Integration, and Advanced Malware Protection
  • Dynamic Cloud Access: Cloud On-Ramp for SaaS and IaaS (AWS, Azure & GPC)
  • API and Programmatic Interaction via Python

Module 4: Deeper Insight into Cisco SD-WAN Security

  • Designing Security Requirements within Cisco SD-WANDIA SecurityDirect Cloud Access SecurityGuest User SecurityCompliance Requirements
  • Security Implementation at the Branch Site
  • Implementing Zone Based Firewalls on Cisco WAN Edge
  • Implementing UTD on Cisco WAN EdgeConfiguring URL FilteringConfiguring Snort IPSBest Practices for UTD setup (Based on production deployment experiences)
  • Implementing Advanced Malware ProtectionConfiguring AMPOverview of integration with Threat Grid

Module 5: Designing and Implementing DNS Security

  • Prerequisite check before integrating Umbrella with Cisco SD-WANMaking sure you have the correct licensingPlatform support checkInternet Connectivity check
  • Walking through the Umbrella DashboardDashboard OverviewDNS Policy GUI OverviewFirewall Policy GUI OverviewWeb Policy GUI OverviewUmbrella AD/SAML Integration Overview (optional)
  • Integrating Cisco Umbrella for DNS SecurityUmbrella API Integration
  • Configuring the DNS Encryption PolicyExcluding the local domainsConfiguring the Security Policy in vManageImplementing the policy at the DIA Sites
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 6: Cisco SD-WAN and Cisco Umbrella SIG Integration

  • SIG Integration Overview
  • Configuring Cisco vManage Templates for SIG Tunnel CreationUsing the pre-configured Feature Templates in vManage 20.X
  • Adding the SD-WAN Routers and Sites in Umbrella IdentitiesValidate that the routers show up from the Umbrella Dashboard
  • Designing and Configuring Policy for SIG RedirectionSetting up the vSmart Centralized Policies for SIG Redirection on DIA Traffic
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 7: Cisco SD-WAN and Cisco Umbrella Cloud Firewall Integration

  • Umbrella Cloud Firewall Integration Overview
  • Configuring Cisco vManage Templates for Firewall Tunnel CreationUsing the pre-configured Feature Templates in vManage 20.X
  • Adding the SD-WAN Routers and Sites in Umbrella IdentitiesValidate that the routers show up from the Umbrella Dashboard
  • Designing and Configuring Policy for Firewall RedirectionSetting up the vSmart Centralized Policies for Umbrella FW Redirection on DIA Traffic
  • VerificationChecking the logs on Umbrella DashboardChecking the vManage Security Dashboard

Module 8: Troubleshooting Umbrella Integration

  • Troubleshooting DNS SecurityAPI Integration not workingDNS for local domain failingNo redirection to Cisco Umbrella for external domains
  • Troubleshooting SIG and FirewallMaking sure the IPSec Tunnels to Troubleshooting the vManage policies for redirectionLoad balancing using vManage policiesReviewing logs in Umbrella
  • Checking Alarms and NotificationsChecking Alarms on vManageChecking Alarms on Cisco Umbrella

Lab Outline: Labs are designed to assure learners a whole practical experience, through the following practical activities:

  • Onboard Edge
  • Onboard Edge via ZTP
  • Onboard vSmart Controller
  • AVC integration and Traffic Visibility
  • Application Aware Routing Lab
  • Local DIA and Regional DIA
  • Backup and Restore using Python API
  • Intra Zone Firewall
  • Inter Zone Firewall
  • UTD integrationURL FilteringSnort IPS
  • Umbrella IntegrationDNS PolicyWeb Policy
  • SIG Tunnel Creation
  • SIG Tunnel Redirection Policy
  • Configuring Policy for Umbrella Firewall Redirection
  • Trouble Ticket 1
  • Trouble Ticket 2
  • Trouble Ticket 3
|
View Full Schedule

Schedule

5 options available

  • Mar 24, 2025 - Mar 26, 2025 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Jun 16, 2025 - Jun 18, 2025 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Aug 11, 2025 - Aug 13, 2025 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Oct 20, 2025 - Oct 22, 2025 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote
  • Dec 8, 2025 - Dec 10, 2025 (3 days)
    Virtual | 10:00 AM 6:00 PM EDT
    Language English
    Select from 1 options below
    Virtual |10:00 AM 6:00 PM EDT
    Virtual | 10:00 AM 6:00 PM EDT
    Enroll
    Enroll Add to quote

FAQ

Does the course schedule include a Lunchbreak?

Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does Ascendient Learning deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

What does vendor-authorized training mean?

As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.

Is the training too basic, or will you go deep into technology?

It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.

How up-to-date are your courses and support materials?

We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.

Are your instructors seasoned trainers who have deep knowledge of the training topic?

Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.

Do you provide hands-on training and exercises in an actual lab environment?

Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.

Will you customize the training for our company’s specific needs and goals?

We will work with you to identify training needs and areas of growth.  We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.

How do I get started with certification?

Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.

Will I get access to content after I complete a course?

You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.

How do I request a W9 for Ascendient Learning?

View our filing status and how to request a W9.

Reviews

Course was great and informative. The instructor had a good flow and was very personable.

Instructor knew her stuff. Long time in the industry. Course was easy to follow and very informative.

ExitCertified provided us with a great opportunity to learn more about React and in easy to follow way.

The technical data in the AWS Solutions Architect course was very thorough.

ExitCertified gave me some good trainings and I got to learn through doing labs.