VMware SD WAN Technical Overview EN
VMware SD WAN Technical Overview EN
VMware SD WAN Technical Overview EN
by VeloCloud®
Technical Overview
Speaker Name
Role
Date
VeloCloud®️ Orchestrator
VMware SD-WAN Orchestrator
(VCO)
VeloCloud®️ Gateway
VMware SD-WAN Gateway
(VCG)
VeloCloud®️ Controller
VMware SD-WAN Controller
(VCC)
VeloCloud®️ Edge
VMware SD-WAN Edge
(VCE)
Cable
DSL
Branch Data center
LTE
Cloud Services
Sub-optimal Complex
Inefficient
traffic flow to manage
50-80% backhaul
50% has hybrid WAN SaaS IaaS/PaaS
Dropbox
Lifting & shifting to cloud Salesforce.com
Office365
GCP AWS
DATA
LEASED LINES DATA CENTER
CENTER
Transport independent
Zero touch deployments, Direct cloud access with
performance for the most
simplified operations, performance, reliability
demanding apps, leverages
one-click service insertion and security
economical bandwidth
VMware SD-WAN
VMware SD-WAN
1
Orchestrator
1 Orchestrator
SaaS
2
Public
Internet
Branch site
with VMware Enterprise data center
2 Cloud Gateway SD-WAN Edges
Dynamic Multipath
via VMware SD-WAN
Optimization
Gateway
3
Private
Network/MPLs
Edge 510 Edge 520 Edge 520v Edge 540 Edge 840 Edge 840v Edge 2000
10 Mbps
50 Mbps
100 Mbps
10 Gbps
1 Gbps 2 Gbps
IT admin adds a new VMware SD-WAN VMware SD-WAN Edge with Office admin plugs in the device and
Edge in the customer account. factory default config is shipped connects to the Internet through
to the remote site. VMware SD-WAN Edge WLAN/LAN
IT admin generates an activation key Office admin powers up the device Office admin clicks on activation link
and emails it to the installer. and connects it to the internet. in the email. Edge is activated.
Regions
29
AZ’s
32
VMware SD-WAN Data plane function Control plane function Important control VMware SD-WAN
Gateway software has (Optional) (Mandatory) plane traffic protected Controller = Same
both data plane and Handoff traffic Bandwidth test by IPSec VMware SD-WAN
control plane to Non-VMware Route update & Gateway software with
SD-WAN site distribution data plane disabled
Handoff traffic to SaaS WAN IPs discovery
& resolution
1 Policy config
VMware SD-WAN Gateway is also transparent
to the end enterprise
IPSec
IPSec
99.99% Availability
Browsers, cURL
VMware JSON-RPC API over HTTPS transport
SD-WAN between the client and VMware SD-WAN
Orchestrator Orchestrator
API
MSP Portal
Partner A Partner B Partner C vco.velocloud.net
Customers
Enterprise Portal
Customer A Customer B Customer C Customer D vco.velocloud.net
TLS 1.2
Configuration update
Polling model simplifies the NAT/firewall Automatically switch to underlay VMware SD-WAN Gateway NAT
requirement. VMware SD-WAN Edge if heartbeat through the overlay fails all the heartbeats toward
always initiates traffic toward VMware SD- the VMware SD-WAN Orchestrator
WAN Orchestrator.
SD-WAN
public overlay Internet
SMS
Traps
SNMP
UDP/2426
VMware SD-WAN VMware SD-WAN VMware SD-WAN VMware SD-WAN VMware SD-WAN
Orchestrator Controller Orchestrator Controller Orchestrator
Branch Edges
Branch Edges Branch Edges
Branch Office
with VMware SD-WAN Edge Data center
Internet with VMware SD-WAN VMware SD-WAN Edge
EDGE (HUB)
(VMware SD-WAN Edge) on-
DMPO premises (physical or VNF)
MPLS
Branch Office VMware SD-WAN
with VMware SD-WAN Edge
Orchestrator Normally decision for
On-premises on premises is due to regulation
or security concern
LTE
DMPO
2500+ Applications
New flow
Is this flow
Perform DPI
to a known destination?
Update the
dynamically
learned DB
On Demand Remediation
VMware SD-WAN
Non-SD-WAN
Available
Link A: Private Wired
Prefer application on a path but steer away
if the overlay fails
Example: Web Browsing
Web
Browsing Link B
Business
Collaboration
Audio/Video
35 15 1
Real-Time Real-Time
Infrastructure,
Authentication, IM, Web, Proxies,
Remote Desktop,
Business App
Management,
Network Services,
Games, Media,
Social
20 7 1
Transactional Tunneling Transactional
Critical SaaS
2 applications & Internet
backhaul to CWS
Non-critical Internet
1 traffic, e.g. Netflix
Direct
Multipath to
closest gateway
Internet/MPLS
Branch edge
Backhaul to
selected VMware
SD-WAN Edges
IPSec
VPC Router
Static tunnel to VMware SD-WAN
Edge Hubs
Branch Site Enterprise
IPSec
Internet DC
Dynamic
E2E Dynamic tunnel between branch
tunnel Enterprise VMware SD-WAN Edges for scale
data center
Initial traffic
Leverage distributed VMware SD-WAN Gateways to facilitate For security conscious and hybrid sites
E2E traffic Define list of hubs to facilitate E2E traffic
VMware SD-WAN Gateway used for both data/ VMware SD-WAN Gateway used for control plane only
control plane
Initial traffic hairpins to hub while dynamic E2E tunnel is built
Initial traffic goes through VMware SD-WAN Gateway while
dynamic E2E tunnel is built
Step 1
VMware SD-WAN VMware SD-WAN Edge receives a list of VMware SD-WAN Gateway
Gateway IP and Bandwidth, ISP discovery,
and hub IPs to connect to IPs and hubs from VMware SD-WAN Orchestrator
list of hubs
VMware SD-WAN Edge builds the control tunnel to the VMware SD-
WAN Gateway to learn about its bandwidth, ISP, and hub IPs to
connect to
Internet
MPLS
Branch Hub Step 2
3
Separation between different private tunnels by
tagging each private network with different name
MPLS1 MPLS2 Internet
IPSec
Use IKE DPD to detect IPSec tunnel
failure and notify the VMware
SD-WAN Edge
Routing Hub
Protocol
Routing Route
L3 SW Protocol Redistribution
Support overlay and underlay Underlay route options: OSPF and/or BGP underlay Underlay routes are
routes over the same interface static (with IP SLA), OSPF, BGP routing protocol at each site redistributed to the overlay
and vice versa while retaining
the BGP attributes
I can reach A
A A
Simple and deterministic routing Need careful routing plan to avoid asymmetric
and sub-optimal routing
This is due to mixing overlay and underlay networking, not
VeloCloud or SD-WAN issue
MPLS MPLS
SD-WAN SD-WAN SD-WAN SD-WAN
Hybrid Branch Transit Site Hybrid Branch Transit Site
SD-WAN SD-WAN
Overlay Overlay
• Traffic to/from non-SD-WAN sites go through hubs • Traffic to/from non SD-WAN sites go directly to MPLS
to reach SD-WAN sites
• May be preferred if there is a lot of communication
• Simple to control policy. Eliminate BGP from branch between SD-WAN and non-SD-WAN sites
• If non-SD-WAN sites are high BW, allow SD-WAN sites • Utilize uplink feature on the BGP neighbor toward MPLS
to use combined link BW cloud to stop a branch from being transit
• May introduce latency due to backhauling
BGP BGP
Route learning
from legacy
Overlay flow control
protocol, e.g.
OSPF, BGP
Control Plane
Exchange
through
overlay
Voice
PCI VMware
VMware SD-WAN
SD-WAN Edge
Gateway
Enable segmentation globally per customer Overlay tunnel is shared by all segments for scalability
Media
Signaling
Overlapping IP
in different segments
Corp SBC
10.2.0.0/24
Guest Corp
10.2.0.0/24
Branch 2
VMware
SD-WAN Edge Guest
Guest
10.3.0.0/24
PCI
PCI PCI
Network
10.3.0.0/24 Retail Store
VMware SD-WAN optional PCI Certified (AOC) Event and firewall logs / APIS
Built-in certification server
hosted Orchestrator and Controller
EntA-Hub
SaaS
Public
Internet
Private /MPLs
IPSec
IPSec
Per-app service insertion
when connect through
VMware SD-WAN Gateway
IPSec
Simplify tunnel configuration to
cloud web security
SD-WAN CPE
VRRP
with VRRP To Core Switch
(Campus/DC)
SW and routing
protocol VMware SD-WAN
Edge Cluster
OSPF/BGP
….
Hybrid Site
SD-WAN CPE
Internet only Data center/Regional Hub
BGP BGP
PE
PE PE
OSPF BGP
During transition, use the hub as transit to Run BGP with PE Run BGP with PE
reach non-SD-WAN sites Run OSPF with enterprise LAN Run BGP with enterprise LAN
Static route & connected subnets Redistribute between BGP, OSPF, Redistribute BGP into overlay
automatically advertised into overlay and overlay Preserve BGP attributes: community, AS-
path, local-pref, MED
Common deployment in
BGP the data center with dual
core switches
CLOUD
BRANCH (uses stroke, DATA CENTER/DC
change weight as you see fit)