Managing the SD-Routing Device Using Cisco SD-WAN Manager
Information About Using Cisco SD-WAN Manager to Monitor the SD-Routing Devices
This feature enables basic management capabilities for Cisco IOS XE devices operating in non-SD-WAN mode, referred to as SD-Routing devices from Cisco IOS XE 17.12.1a onwards. Cisco SD-WAN Manager serves as a single network management system (NMS) for managing and monitoring all Cisco IOS XE routers, simplifying solution deployments.
Note: The minimum software version required is Cisco IOS XE 17.12.1a and Cisco SD-WAN Release 20.12.1.
Figure 1 illustrates the concept of managing SD-Routing Devices.
Benefits of Managing the SD-Routing Devices Using Cisco SD-WAN Manager
- Utilizes a single NMS (Cisco SD-WAN Manager) for both Cisco Catalyst SD-WAN and SD-Routing deployments in an enterprise network.
- Allows co-existence of Cisco SD-WAN and SD-Routing devices on the same Cisco SD-WAN Manager.
Prerequisites
To onboard SD-Routing devices, the following prerequisites must be met:
- Enable netconf-yang models for DMI, which is necessary for management via Cisco SD-WAN Manager.
- Devices operating in autonomous mode require basic manual configuration to establish secure control connections with controllers (Cisco SD-WAN Validator and Cisco SD-WAN Manager). This includes configuring system properties (System-IP, Site-ID, Organization-Name), Cisco SD-WAN Validator information (IP address or FQDN), and interface configuration (physical interface with IP address and subnet mask, dynamic routing or default route for reachability).
Limitations
- Onboarding of Cisco SD-routing devices onto Cisco SD-WAN Manager is only supported with universalk9 images.
- Speed Test for SD-routing devices is not supported through Cisco SD-WAN Manager.
- Rommon upgrade is not supported through Cisco SD-WAN Manager; use the CLI option for upgrades.
- Cisco SD-routing devices can only have one control connection to Cisco SD-WAN Manager over a single WAN Edge interface.
- Cisco SD-routing devices will not have any active connection with Cisco SD-WAN Controller.
Onboarding the SD-Routing Devices
This section details the workflows for onboarding SD-Routing devices, including Automated Onboarding, Bootstrap Onboarding, and Manual Onboarding.
Figure 2 shows the Cisco SD-Routing Devices Onboarding Options.
Supported WAN Edge Devices
The following table lists the supported WAN Edge platforms and their available onboarding options:
Platforms | Automated | Bootstrap | Manual |
---|---|---|---|
Cisco ASR 1000 Series Aggregation Services Routers | |||
ASR1001-HX | Yes | Yes | Yes |
ASR1002-HX | Yes | Yes | Yes |
Cisco 4400 Series Integrated Services Routers | |||
Cisco 4431 ISR | Yes | Yes | Yes |
Cisco 4451 ISR | Yes | Yes | Yes |
Cisco 4461 ISR | Yes | Yes | Yes |
Cisco 4300 Series Integrated Services Routers | |||
Cisco 4321 ISR | Yes | Yes | Yes |
Cisco 4331 ISR | Yes | Yes | Yes |
Cisco 4351 ISR | Yes | Yes | Yes |
Cisco 4200 Series Integrated Services Routers | |||
Cisco 4221 ISR | Yes | Yes | Yes |
Cisco 100 Series Integrated Services Routers | |||
Cisco 1000 ISR | Yes | Yes | Yes |
Cisco Catalyst 8000V Series Edge Platforms | |||
Cisco Catalyst 8000V | Not applicable | Yes | Yes |
Note: Automated onboarding is applicable only for hardware devices. | |||
Cisco Catalyst 8200 Series Edge Platforms | |||
C8200-1N-4T | Yes | Yes | Yes |
C8200L-1N-4T | Yes | Yes | Yes |
Cisco Catalyst 8300 Series Edge Platforms | |||
C8300-1N1S-4T2X|6T | Yes | Yes | Yes |
C8300-2N2S-4T2X|6T | Yes | Yes | Yes |
Cisco Catalyst 8500 Series Edge Platforms | |||
C8500-12X4QC | Yes | Yes | Yes |
C8500-12X | Yes | Yes | Yes |
C8500L-8S4X | Yes | Yes | Yes |
C8500-20X6C | Yes | Yes | Yes |
Onboarding the SD-Routing Devices Using Automated Workflow (Greenfield)
To onboard SD-routing devices using the automated workflow, follow these steps:
- Configure the Plug and Play Connect Portal.
- Configure Cisco SD-WAN Manager using the quick connect workflow.
- Bring up the device in Day-0 mode.
Configuring the Plug and Play Connect Portal
To configure the PnP Connect portal:
Before you begin: Ensure an active connection to the PnP Connect portal, an active Smart Account, and Virtual Account. Use a CCO ID associated with the Smart Account or Virtual Account admin.
- Go to software.cisco.com > Network Plug and Play > Manage Devices and verify access to Smart Account and Virtual Account.
- Create a Controller Profile and upload the root-CA if it is for an Enterprise network. (If the overlay network is Cisco PKI, no certificate upload is needed).
- Enter the Controller Profile with controller type as VBond and click Next.
- Enter the required parameters in the Add Controller Profile and click Next.
- Add the device to PnP Connect. In the Device Mode field, select AUTONOMOUS for devices in SD-Routing mode from the drop-down list.
Note: PnP Connect Sync can only be enabled after entering Smart Account credentials.
Configuring Cisco SD-WAN Manager Using Quick Connect Workflow
To configure Cisco SD-WAN Manager using the Quick Connect workflow:
- From the Cisco SD-WAN Manager menu, navigate to Workflows > Quick Connect.
- Click Get Started.
- Click Next.
- If the provisioning file (.csv or .viptela from PnP) has not been uploaded to Cisco SD-WAN Manager, use either .csv upload, .viptela upload, or the Sync Smart Account option to add the device. If the device is already added, select the skip for now option.
- Click Sync Smart Account. The device should appear in the table.
- Click Next.
- In the Add and Review Device Configuration dialog box, enter the Site-ID, System-IP, and Hostname, then click Apply.
- Click Next.
- Add any optional tags and click Next.
- To verify the added device, navigate to Configuration > Devices and click enable Device Model in Table Settings.
- A list of routers with detailed information is displayed. To confirm devices are added, select Configuration > Certificates.
Note: The .csv file is applicable only for hardware devices. The .viptela file is applicable for both hardware and software devices.
Bringing Up the SD-Routing Device
To bring up the SD-Routing device:
- Bring up the device in Day-0 state. If not in Day-0 state, use controller-mode reset or writer erase with reload to bring it to Day-0 state.
- Ensure the device obtains an IP address via DHCP on an interface other than GigabitEthernet0. Verify reachability to devicehelper.cisco.com and the Cisco SD-WAN Validator.
- The device control connection will establish with Cisco SD-WAN Manager.
- Verify the control connection status on the Edge device using the
show sd-routing connections summary
command. The output shows peer details, protocol, system IP, site ID, and connection state. - Verify the control connection status on Cisco SD-WAN Manager.
Onboarding the SD-Routing Devices Using Bootstrap (Brownfield)
To onboard an SD-Routing device using bootstrap:
- From the Cisco SD-WAN Manager menu, navigate to Workflows > Quick Connect.
- Click Get Started.
- Click Next.
- If the provisioning file (.csv or .viptela from PnP) has not been uploaded to Cisco SD-WAN Manager, use either .csv upload, .viptela upload, or the Sync Smart Account option to add the device. If the device is already added, select the skip for now option.
- Select the device to onboard and click Next.
- In the Add and Review Configuration dialog box, enter the Site-ID, System-IP, and Hostname, then click Apply.
- To verify the added device, navigate to Configuration > Devices or Configuration > Certificates and click enable Device Model in Table Settings.
- Ensure the device is in a valid state from the Configuration > Certificate page.
- From the Cisco SD-WAN Manager menu, choose Configuration > Devices.
- For Cisco SD-Routing software devices (Cisco c8000V), generate the bootstrap configuration and onboard the device:
- Click ... in the right pane and choose Generate Bootstrap Configuration.
- Choose the Cloud-init option and enter a name for the VPN0 Interface, then click OK. (Ensure DHCP is enabled on the selected interface and it is reachable to Cisco SD-WAN Validator and Cisco SD-WAN Manager. For software devices, use only GigabitEthernet1 as the VPN0 interface).
- Click Download to download the image. Sample images:
ciscosdwan_cloud_init.cfg
,ciscosdwan_cloud_init_with_ent_cert.cfg
. - For cloud-based controllers, the downloaded bootstrap file can be added as a user data field during device deployment, bringing up the controller in SD-Routing mode and establishing connections.
- For hardware devices, generate the bootstrap and onboard the device:
- Click Export Bootstrap Configuration.
- Select the SD-Routing checkbox. In the Export Bootstrap Configuration dialog box, enter the WAN Interface name. (The VPN 0 interface name may vary; specify based on the model).
- Click Generate Generic Configuration to download the generic .cfg bootstrap file applicable for hardware devices and rename it as
ciscosdawn.cfg
. (Ensure DHCP is enabled on the selected interfaces and they are reachable to Cisco SD-WAN Validator and Cisco SD-WAN Manager). The bootstrap file contains organization name, Cisco SD-WAN validator IP, and root-CA certificates. - Copy the bootstrap file to the device bootflash as
ciscosdwan.cfg
. - Execute the command:
sd-routing bootstrap load bootflash:ciscosdwan.cfg
. The command output confirms extraction and prompts for application. - Verify control connection using
show sd-routing system status
,show sd-routing system status
, andshow sd-routing local-properties summary
commands.
Note: The .csv file is applicable only for hardware devices. The .viptela file is applicable for both hardware and software devices.
Onboarding the Devices Manually (Brownfield)
To onboard SD-Routing devices manually:
- From the Cisco SD-WAN Manager menu, navigate to Workflows > Quick Connect.
- Click Get Started.
- Click Next.
- If the provisioning file (.csv or .viptela) from PnP has not been uploaded to Cisco SD-WAN Manager, use either .csv upload, .viptela upload, or the Sync Smart Account option to add the device. If the device is already added, select the skip for now option.
- Select the device to onboard and click Next.
- In the Add and Review Configuration dialog box, enter the Site-ID, System-IP, and Hostname, then click Apply.
- To verify the device, navigate to Configuration > Devices and click enable Device Model in Table Settings.
- A list of routers is displayed. To verify devices are added, select Configuration > Certificates.
- Perform one of the following based on the device type:
- For hardware devices, enter initial day-0 configurations using IOS commands after a system boot up.
- For Cisco SD-Routing software devices, deploy the Cisco c8000v in AWS or Azure without the bootstrap.
- Configure minimum parameters to enable the control connection on Cisco SD-WAN Manager. Example configuration includes enabling netconf-yang, sd-routing, setting organization-name, site-id, system-ip, vbond IP and port, and WAN-interface, along with IP routing.
- Configure required parameters to enable SD-Routing mode: Ensure the interface is configured with a static IP or DHCP, is in a no-shutdown state, and configure Validator IP or Name, System-IP, Site-ID, Organization-Name, and WAN-Interface.
- Verify feature enablement by checking the status of the vdaemon process using commands like
show platform software yang-management process state
andshow platform software process list r0 name vdaemon
. - If the overlay network is for an enterprise, install root certificates using
request platform software sd-routing root-cert-chain install bootflash:cacert.pem
. For Cisco PKI, this step is not needed. - Perform one of the following based on the device:
- For Cisco 8000v devices, copy the root certificate from the CA to the device.
- Cisco devices are loaded with PKI and symantec root-certificates by default. For enterprise root-certificates, use
request platform software sd-routing root-cert-chain install <path-to-root-cert>
. - Install client enterprise certificates (applicable for manually onboarding software devices).
- Generate a Certificate Signed Request (CSR) using
request platform software sd-routing csr upload <path-to-create-csr>
. - Copy the generated CSR file to the Enterprise CA directory, sign the certificate using the root key and root CA certificate, and generate the pem certificate file.
- Copy the generated certificate.pem file to the device and install it using
request platform software sd-routing certificate install <path-to-certificate-file>
. - Verify the installation status of the certificates using
show sd-routing local-properties summary
. The output shows certificate status, validity, and details like DNS name, site-ID, system-IP, chassis number, and serial number. - Onboard the device on Cisco SD-WAN Manager. When installing the client certificate, ensure the Chassis number and Serial number are obtained (using
show sd-routing local-properties summary
orshow sd-routing certificate serial
) and uploaded to Cisco SD-WAN Manager WAN Edge List usingvedge add chassis-num <Chassis id> org-name <Org Name> serial-num <Serial number>
on all controllers, or by creating and uploading a .viptela file. - Verify the control connection status on Cisco SD-WAN Manager using
show sd-routing connections summary
.
Note: The .csv file is applicable only for hardware devices. The .viptela file is applicable for both hardware and software devices.
Onboarding the Device to Cisco SD-WAN Manager Using One Touch Provisioning
To perform one-touch provisioning:
Before you begin:
- The device must be in autonomous mode, with PnP discovery stopped. It should have a startup configuration or any configuration, but not be in Day-0 state.
- The device must be configured to reach Cisco SD-WAN Validator and Cisco SD-WAN over the WAN interface.
- The device must have the minimum required configuration for the SD-Routing feature to communicate with controllers.
One-touch provisioning eliminates the need to add WAN Edge devices to Cisco SD-WAN Manager via .csv, .viptela, or sync smart account. It also bypasses the manual or bootstrap configuration for SD-routing mode when the device is not added to Cisco SD-WAN Manager.
- From the Cisco SD-WAN Manager menu, navigate to Administration > Settings and enable One Touch Provisioning.
- Check if One Touch Provisioning is Enabled. If yes, proceed to Step 5.
- If One Touch Provisioning is Disabled, click Edit.
- Set the Enable Claim WAN Edges setting to Enabled and click Save.
- Go to Configuration > Devices > Unclaimed Devices.
- Select the device(s) to claim and click Claim Device(s).
- The device is removed from the Unclaimed Devices List and appears in the WAN Edge List.
- Verify the device status using
show sd-routing system status
andshow sd-routing local-properties summary
commands.
Unprovisioning the Feature
To unprovision the feature:
- Remove the SD-Routing feature configuration from the device.
- Invalidate the device (refer to step 4 in the "Onboarding the Devices Manually (Brownfield)" section).
- Delete the device from Cisco SD-WAN Manager: Navigate to Configuration > Devices, select the device from the WAN Edge List, click Delete WAN Edge, and confirm the deletion.
Note: Disabling the feature deletes all certificates. Backup and reinstall certificates upon re-enabling.
Software Image Management
Cisco SD-WAN Manager supports uploading prepackaged Cisco virtual machine images, tar.gz files, or qcow2 format images. A scaffold file is mandatory for qcow2 images. Cisco SD-WAN Manager communicates with NETCONF, a standard protocol for retrieving operational data and editing configuration data.
The upgrade workflow for SD-Routing devices is similar to Controller mode workflows.
Note: The minimum software version required is Cisco IOS XE 17.12.1a.
Software Upgrade Using CLI
To upgrade the software using CLI:
Before you begin:
- Check Disk Space: Ensure sufficient bootflash space for image download and expansion.
- Image Repository Check: Verify reachability to the remote server.
- Auto Boot Enable: Confirm that auto boot is enabled on the device.
- Download the Cisco IOS XE Release 17.12 image from software.cisco.com.
- Upload the image to the device.
- Install the new software using the
install add file <bootflash:/file name> activate commit
command and activate it. - Verify the upgrade using the
install commit
command.
Note: This is an interactive command that prompts for review and acceptance. It fails if unsaved configuration exists; use write memory
and reinstall software.
Add Software Images to the Repository
To upgrade software on an SD-Routing device or Cisco SD-WAN Manager, add the software image to the Cisco SD-WAN Manager software repository. Refer to the "Manage Software Repository" section of the Cisco SD-WAN Monitor and Maintain Configuration Guide for details.
Software Upgrade Using Cisco SD-WAN Manager
To upgrade the software image on a device:
Before you begin:
- This procedure does not support downgrading. For downgrades, refer to the Cisco SD-WAN Getting Started Guide.
- For Cisco SD-WAN Manager cluster upgrades, see "Upgrade Cisco vManage Cluster".
- Check Auto Boot Enable: Confirm that auto boot is enabled on the device.
- From the Cisco SD-WAN Manager menu, navigate to Maintenance > Software Upgrade.
- Click WAN Edge, Controller, or vManage based on the device type.
- Select the devices to upgrade by checking the box on the far left. (For clusters, select all nodes).
- Click Upgrade.
- In the Software Upgrade slide-in pane:
- Choose the server (vManage, Remote Server, or Remote Server - vManage) from which the device should download the image. Ensure the device can reach the remote server if selected. Note valid characters for User ID, Password, and URL Name/Path when using a remote server.
- For SD-WAN Manager, select the image version from the Version drop-down list.
- For Remote Server - SD-WAN Manager, choose the vManage OOB VPN and the image version.
- Check the Activate and Reboot checkbox. (This option is not available for Cisco SD-WAN Manager software upgrades; activation and reboot must be done manually).
- Click Upgrade.
- The device restarts with the new software version, retaining its configuration. The Task View page shows the upgrade progress.
- Wait for the upgrade to complete (indicated by "Success" in the Status column).
- Verify the upgrade by navigating to Maintenance > Software Upgrade and confirming the Current Version and Reachability columns.
Note: If the control connection does not re-establish within the timeout, the device reverts to the previous software image. Upgrading VEdge software to a version higher than the controller may cause incompatibilities; upgrade controller software first.
Delete a Software Image
To delete a software image from an SD-Routing device:
- Navigate to Maintenance > Software Upgrade.
- Click WAN Edge, Controller, or Cisco SD-WAN Manager.
- Select the device(s) from which to delete a software image.
- Click Delete Available Software.
- Choose the software version to delete in the dialog box and click Delete.
View Log of Software Upgrade Activities
- From the Cisco SD-WAN Manager toolbar, click the Tasks icon.
- Click the Arrow icon to view task details, including status and device-specific information.
Monitoring the Device Using Cisco SD-WAN Manager
The Monitor window provides a consolidated, real-time view of monitoring components and services for Cisco SD-Routing devices. Monitoring options include SSH Terminal, Ping, and Traceroute. System status information can be collected into a compressed .tar file.
Controller-managed mode enables this feature by default.
Monitoring the Device Using SSH
To establish an SSH connection for monitoring:
- From the Cisco SD-WAN Manager menu, navigate to Monitor > Devices.
- Select a device from the list.
- For a single device, click ... and choose SSH Terminal. Alternatively, go to Tools > SSH Terminal.
- Enter the password twice to establish the connection.
- Execute
show
commands in the terminal to monitor the device.
Pinging the Device
To ping a device:
- From the Cisco SD-WAN Manager menu, navigate to Monitor > Devices.
- Select a device from the list.
- For a single device, click ... and choose Ping.
- Enter the destination IP address on the Monitor page.
- Click Ping. Results are displayed below.
Tracing the Route
To trace the route to a device:
- From the Cisco SD-WAN Manager menu, navigate to Monitor > Devices.
- Select a device from the list.
- For a single device, click ... and choose Trace Route.
- Enter the destination IP address on the Trace Route page.
- Click Start to trace the route.
Alarms and Events
Devices report events to Cisco SD-WAN Manager, which filters, correlates, and consolidates them into alarms. The Alarms screen displays detailed information about alarms generated by SD-Routing devices.
Monitoring the Alarms and Events
Alarms can be viewed from the Cisco SD-WAN Manager dashboard (Bell icon) or the Alarms screen (Monitor > Alarms). Alarms are grouped into Active or Cleared and default to the last 24 hours. Click ... for an alarm and then Alarm Details to view probable cause, impacted entities, and other details.
Admin-Tech Files
Admin-tech files, collections of system status information for troubleshooting, can be viewed and managed. You can generate these files and download them to your local device.
Requesting the Admin-tech File Using Cisco SD-WAN Manager
To request an Admin-tech file:
- From the Cisco SD-WAN Manager menu, navigate to Tools > Operational Commands.
- For a single device, click ... and choose Generate Admin Tech.
- In the Generate admin-tech File window, optionally limit contents:
- Uncheck Include Logs to omit log files.
- Check Include Cores to include core files (stored in bootflash:/core or harddisk:/core).
- Check Include Tech to include device process details, memory, and operations.
- Click Generate. The file is named hostname-date-time-admin-tech.tar.gz.
- To view generated files, navigate to Tools > Operational Commands > Show Admin Tech List.
Requesting the Admin-tech File Using CLI
Use the request tech-support
command to generate the admin-tech file. The output shows the collection process and the final bundle file path.
Monitoring the Real Time Data
To view real-time data for a device:
- From the Cisco SD-WAN Manager menu, navigate to Monitor > Devices.
- Select a device from the list.
- For a single device, click ... and choose Real Time.
- Select the category of data from the Device Options drop-down list. Results are displayed.
Configuration Examples
This section provides configuration examples.
Example: Enabling Control Connection to Cisco SD-WAN Manager
Configuration commands to enable control connection:
(config)
sd-routing
(config-sd-routing)
system-ip 172.16.255.15
(config-sd-routing)
organization-name viptela
(config-sd-routing)
vbond ip 10.0.12.26
(config-sd-routing)
site-id 500
(config-sd-routing)
wan-interface GigabitEthernet2
Example: Verification of Enable Control Connection
Use the show platform software yang-management process state
command to check the connection status. The output indicates the status of various processes like nesd, syncfd, ncsshd, dmiauthd, nginx, ndbmand, and pubd.
Use the show platform software process list r0 name vdaemon
command to check the vdaemon status, showing details like Process ID, Parent Process ID, Status, User Time, Kernel Time, etc.
Example: Installing the Root Certificate
Command to install the root certificate:
Device# request platform software sd-routing root-cert-chain install bootflash:root-ca.crt
Example: Verifying the Root Certification Installation
Use the show sd-routing local-properties summary
command to check the root certificate installation status. The output includes details like personality, organization-name, root-ca-chain-status, certificate-status, certificate-validity, system-ip, chassis-num/unique-id, and serial-num.
Troubleshooting
This section provides commands for troubleshooting common issues when managing and monitoring SD-Routing devices using Cisco SD-WAN Manager:
show version
: Displays the operating mode (e.g., "Router operating mode: Autonomous (SD-Routing)").show platform software yang-management process state
show sd-routing system status
show sd-routing connections summary
show platform software process list r0 name vdaemon
show sd-routing local-properties summary
show sd-routing local-properties wan ipv4
show sd-routing local-properties vbond
show sd-routing connections history
Feature Information for Managing SD-Routing Devices Using vManage
The following table provides release information for the feature described in this module. It lists the software release that introduced support for the feature. Subsequent releases of that train also support the feature unless noted otherwise. Use Cisco Feature Navigator for platform and software image support information.
Feature Name | Releases | Feature Information |
---|---|---|
Managing SD-Routing Devices Using Cisco SD-WAN Manager | Cisco IOS XE Release 17.12.1a | This feature allows management operations for SD-Routing devices using Cisco SD-WAN Manager. It simplifies solution deployments by providing a single NMS for monitoring all SD-Routing devices. |