<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.fastlanetraining.ca/css/xml-course.xsl"?><course productid="23748" language="fr" source="https://portal.fastlanetraining.ca/minose/fr/xml-course/nterone-sdwsec" lastchanged="2026-03-26T09:11:13-04:00" parent="https://portal.fastlanetraining.ca/minose/fr/xml-courses"><title>Cisco SD-WAN Advanced Policy and Security</title><productcode>SDWSEC</productcode><vendorcode>NN</vendorcode><vendorname>NterOne</vendorname><fullproductcode>NN-SDWSEC</fullproductcode><version>1.0</version><objective>&lt;p&gt;Upon completing this course, you will be able to meet the following objectives:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe SD-WAN Architecture&lt;/li&gt;&lt;li&gt;Design Cisco SD-WAN Branch Security&lt;/li&gt;&lt;li&gt;Implement Cisco SD-WAN Secure Internet and Cloud Access&lt;/li&gt;&lt;li&gt;Integrate and Troubleshoot Cisco SD-WAN with a SASE Solution&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;The knowledge and skills that the learner should have before attending this course are as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Knowledge of WAN architectures and routing networking concepts&lt;/li&gt;&lt;li&gt;High-level familiarity with basic network protocols and applications&lt;/li&gt;&lt;li&gt;Familiarity with common application delivery methods&lt;/li&gt;&lt;li&gt;Fundamental Understanding of perimeter security&lt;/li&gt;&lt;li&gt;Basic Cisco SD-WAN familiarity&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;The primary audience for this course is as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Systems Engineers&lt;/li&gt;&lt;li&gt;Technical Solutions Architects&lt;/li&gt;&lt;li&gt;Field Engineers&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1: Cisco SD-WAN Introduction
&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;High-level Cisco SD-WAN Deployment models&lt;/li&gt;&lt;li&gt;Application-level SD-WAN solution&lt;/li&gt;&lt;li&gt;Cisco SDWAN plan for HA and Scalability&lt;/li&gt;&lt;li&gt;Cisco SD-WAN solution components: vManage NMS, vSmart Controller, vBond Orchestrator&lt;/li&gt;&lt;li&gt;Edge Routers (cEdge, vEdge, and Catalyst 8K)&lt;/li&gt;&lt;li&gt;Cloud Based Deployment vs On-Premises Deployment&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 2: Zero Touch Provisioning&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview&lt;/li&gt;&lt;li&gt;User Input Required for the ZTP Automatic Authentication Process&lt;/li&gt;&lt;li&gt;Authentication between the vBond Orchestrator and WAN Edges&lt;/li&gt;&lt;li&gt;Authentication between the Edge Routers and the vManage NMS&lt;/li&gt;&lt;li&gt;Authentication between the vSmart Controller and the Edge Routers&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 3: Cisco SD-WAN Solution&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overlay Management Protocol (OMP)&lt;/li&gt;&lt;li&gt;Cisco SD-WAN Circuit Aggregation Capabilities&lt;/li&gt;&lt;li&gt;Secure Connectivity in Cisco SD-WAN&lt;/li&gt;&lt;li&gt;Performance Tracking Mechanisms&lt;/li&gt;&lt;li&gt;Application Discovery&lt;/li&gt;&lt;li&gt;Dynamic Path Selection&lt;/li&gt;&lt;li&gt;Performance Based Routing&lt;/li&gt;&lt;li&gt;Direct Internet Access&lt;/li&gt;&lt;li&gt;Advanced Routing (OSPF, BGP, LISP, VXLAN, MPLS)&lt;/li&gt;&lt;li&gt;Application Aware Routing&lt;/li&gt;&lt;li&gt;Localized and Centralized Policies (Data and Control)&lt;/li&gt;&lt;li&gt;Cisco SD-WAN In-built Security features: App Aware FW, Talos IPS, URL Filtering, Umbrella Integration, and Advanced Malware Protection&lt;/li&gt;&lt;li&gt;Dynamic Cloud Access: Cloud On-Ramp for SaaS and IaaS (AWS, Azure &amp;amp; GPC)&lt;/li&gt;&lt;li&gt;API and Programmatic Interaction via Python&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 4: Deeper Insight into Cisco SD-WAN Security &lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Designing Security Requirements within Cisco SD-WAN&lt;ul&gt;
&lt;li&gt;DIA Security&lt;/li&gt;&lt;li&gt;Direct Cloud Access Security&lt;/li&gt;&lt;li&gt;Guest User Security&lt;/li&gt;&lt;li&gt;Compliance Requirements&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Security Implementation at the Branch Site&lt;/li&gt;&lt;li&gt;Implementing Zone Based Firewalls on Cisco WAN Edge&lt;/li&gt;&lt;li&gt;Implementing UTD on Cisco WAN Edge&lt;ul&gt;
&lt;li&gt;Configuring URL Filtering&lt;/li&gt;&lt;li&gt;Configuring Snort IPS&lt;/li&gt;&lt;li&gt;Best Practices for UTD setup (Based on production deployment experiences)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Implementing Advanced Malware Protection&lt;ul&gt;
&lt;li&gt;Configuring AMP&lt;/li&gt;&lt;li&gt;Overview of integration with Threat Grid&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 5: Designing and Implementing DNS Security&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prerequisite check before integrating Umbrella with Cisco SD-WAN&lt;ul&gt;
&lt;li&gt;Making sure you have the correct licensing&lt;/li&gt;&lt;li&gt;Platform support check&lt;/li&gt;&lt;li&gt;Internet Connectivity check&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Walking through the Umbrella Dashboard&lt;ul&gt;
&lt;li&gt;Dashboard Overview&lt;/li&gt;&lt;li&gt;DNS Policy GUI Overview&lt;/li&gt;&lt;li&gt;Firewall Policy GUI Overview&lt;/li&gt;&lt;li&gt;Web Policy GUI Overview&lt;/li&gt;&lt;li&gt;Umbrella AD/SAML Integration Overview (optional)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Integrating Cisco Umbrella for DNS Security&lt;ul&gt;
&lt;li&gt;Umbrella API Integration&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Configuring the DNS Encryption Policy&lt;ul&gt;
&lt;li&gt;Excluding the local domains&lt;/li&gt;&lt;li&gt;Configuring the Security Policy in vManage&lt;/li&gt;&lt;li&gt;Implementing the policy at the DIA Sites&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Verification&lt;ul&gt;
&lt;li&gt;Checking the logs on Umbrella Dashboard&lt;/li&gt;&lt;li&gt;Checking the vManage Security Dashboard&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6: Cisco SD-WAN and Cisco Umbrella SIG Integration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SIG Integration Overview&lt;/li&gt;&lt;li&gt;Configuring Cisco vManage Templates for SIG Tunnel Creation&lt;ul&gt;
&lt;li&gt;Using the pre-configured Feature Templates in vManage 20.X&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Adding the SD-WAN Routers and Sites in Umbrella Identities&lt;ul&gt;
&lt;li&gt;Validate that the routers show up from the Umbrella Dashboard&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Designing and Configuring Policy for SIG Redirection&lt;ul&gt;
&lt;li&gt;Setting up the vSmart Centralized Policies for SIG Redirection on DIA Traffic&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Verification&lt;ul&gt;
&lt;li&gt;Checking the logs on Umbrella Dashboard&lt;/li&gt;&lt;li&gt;Checking the vManage Security Dashboard&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7: Cisco SD-WAN and Cisco Umbrella Cloud Firewall Integration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Umbrella Cloud Firewall Integration Overview&lt;/li&gt;&lt;li&gt;Configuring Cisco vManage Templates for Firewall Tunnel Creation&lt;ul&gt;
&lt;li&gt;Using the pre-configured Feature Templates in vManage 20.X&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Adding the SD-WAN Routers and Sites in Umbrella Identities&lt;ul&gt;
&lt;li&gt;Validate that the routers show up from the Umbrella Dashboard&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Designing and Configuring Policy for Firewall Redirection&lt;ul&gt;
&lt;li&gt;Setting up the vSmart Centralized Policies for Umbrella FW Redirection on DIA Traffic&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Verification&lt;ul&gt;
&lt;li&gt;Checking the logs on Umbrella Dashboard&lt;/li&gt;&lt;li&gt;Checking the vManage Security Dashboard&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;Module 8: Troubleshooting Umbrella Integration&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Troubleshooting DNS Security&lt;ul&gt;
&lt;li&gt;API Integration not working&lt;/li&gt;&lt;li&gt;DNS for local domain failing&lt;/li&gt;&lt;li&gt;No redirection to Cisco Umbrella for external domains&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Troubleshooting SIG and Firewall&lt;ul&gt;
&lt;li&gt;Making sure the IPSec Tunnels to Troubleshooting the vManage policies for redirection&lt;/li&gt;&lt;li&gt;Load balancing using vManage policies&lt;/li&gt;&lt;li&gt;Reviewing logs in Umbrella&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Checking Alarms and Notifications&lt;ul&gt;
&lt;li&gt;Checking Alarms on vManage&lt;/li&gt;&lt;li&gt;Checking Alarms on Cisco Umbrella&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>Upon completing this course, you will be able to meet the following objectives:


- Describe SD-WAN Architecture
- Design Cisco SD-WAN Branch Security
- Implement Cisco SD-WAN Secure Internet and Cloud Access
- Integrate and Troubleshoot Cisco SD-WAN with a SASE Solution</objective_plain><essentials_plain>The knowledge and skills that the learner should have before attending this course are as follows:


- Knowledge of WAN architectures and routing networking concepts
- High-level familiarity with basic network protocols and applications
- Familiarity with common application delivery methods
- Fundamental Understanding of perimeter security
- Basic Cisco SD-WAN familiarity</essentials_plain><audience_plain>The primary audience for this course is as follows:


- Systems Engineers
- Technical Solutions Architects
- Field Engineers</audience_plain><outline_plain>Module 1: Cisco SD-WAN Introduction




- High-level Cisco SD-WAN Deployment models
- Application-level SD-WAN solution
- Cisco SDWAN plan for HA and Scalability
- Cisco SD-WAN solution components: vManage NMS, vSmart Controller, vBond Orchestrator
- Edge Routers (cEdge, vEdge, and Catalyst 8K)
- Cloud Based Deployment vs On-Premises Deployment

Module 2: Zero Touch Provisioning


- Overview
- User Input Required for the ZTP Automatic Authentication Process
- Authentication between the vBond Orchestrator and WAN Edges
- Authentication between the Edge Routers and the vManage NMS
- Authentication between the vSmart Controller and the Edge Routers

Module 3: Cisco SD-WAN Solution


- Overlay Management Protocol (OMP)
- Cisco SD-WAN Circuit Aggregation Capabilities
- Secure Connectivity in Cisco SD-WAN
- Performance Tracking Mechanisms
- Application Discovery
- Dynamic Path Selection
- Performance Based Routing
- Direct Internet Access
- Advanced Routing (OSPF, BGP, LISP, VXLAN, MPLS)
- Application Aware Routing
- Localized and Centralized Policies (Data and Control)
- Cisco SD-WAN In-built Security features: App Aware FW, Talos IPS, URL Filtering, Umbrella Integration, and Advanced Malware Protection
- Dynamic Cloud Access: Cloud On-Ramp for SaaS and IaaS (AWS, Azure &amp; GPC)
- API and Programmatic Interaction via Python

Module 4: Deeper Insight into Cisco SD-WAN Security 


- Designing Security Requirements within Cisco SD-WAN
- DIA Security
- Direct Cloud Access Security
- Guest User Security
- Compliance Requirements
- Security Implementation at the Branch Site
- Implementing Zone Based Firewalls on Cisco WAN Edge
- Implementing UTD on Cisco WAN Edge
- Configuring URL Filtering
- Configuring Snort IPS
- Best Practices for UTD setup (Based on production deployment experiences)
- Implementing Advanced Malware Protection
- Configuring AMP
- Overview of integration with Threat Grid

Module 5: Designing and Implementing DNS Security


- Prerequisite check before integrating Umbrella with Cisco SD-WAN
- Making sure you have the correct licensing
- Platform support check
- Internet Connectivity check
- Walking through the Umbrella Dashboard
- Dashboard Overview
- DNS Policy GUI Overview
- Firewall Policy GUI Overview
- Web Policy GUI Overview
- Umbrella AD/SAML Integration Overview (optional)
- Integrating Cisco Umbrella for DNS Security
- Umbrella API Integration
- Configuring the DNS Encryption Policy
- Excluding the local domains
- Configuring the Security Policy in vManage
- Implementing the policy at the DIA Sites
- Verification
- Checking the logs on Umbrella Dashboard
- Checking the vManage Security Dashboard
Module 6: Cisco SD-WAN and Cisco Umbrella SIG Integration


- SIG Integration Overview
- Configuring Cisco vManage Templates for SIG Tunnel Creation
- Using the pre-configured Feature Templates in vManage 20.X
- Adding the SD-WAN Routers and Sites in Umbrella Identities
- Validate that the routers show up from the Umbrella Dashboard
- Designing and Configuring Policy for SIG Redirection
- Setting up the vSmart Centralized Policies for SIG Redirection on DIA Traffic
- Verification
- Checking the logs on Umbrella Dashboard
- Checking the vManage Security Dashboard
Module 7: Cisco SD-WAN and Cisco Umbrella Cloud Firewall Integration


- Umbrella Cloud Firewall Integration Overview
- Configuring Cisco vManage Templates for Firewall Tunnel Creation
- Using the pre-configured Feature Templates in vManage 20.X
- Adding the SD-WAN Routers and Sites in Umbrella Identities
- Validate that the routers show up from the Umbrella Dashboard
- Designing and Configuring Policy for Firewall Redirection
- Setting up the vSmart Centralized Policies for Umbrella FW Redirection on DIA Traffic
- Verification
- Checking the logs on Umbrella Dashboard
- Checking the vManage Security Dashboard

Module 8: Troubleshooting Umbrella Integration


- Troubleshooting DNS Security
- API Integration not working
- DNS for local domain failing
- No redirection to Cisco Umbrella for external domains
- Troubleshooting SIG and Firewall
- Making sure the IPSec Tunnels to Troubleshooting the vManage policies for redirection
- Load balancing using vManage policies
- Reviewing logs in Umbrella
- Checking Alarms and Notifications
- Checking Alarms on vManage
- Checking Alarms on Cisco Umbrella</outline_plain><duration unit="d" days="3">3 jours</duration><pricelist><price country="AT" currency="EUR">4050.00</price><price country="CH" currency="EUR">4050.00</price><price country="ES" currency="EUR">4050.00</price><price country="SE" currency="EUR">4050.00</price><price country="GB" currency="USD">3495.00</price><price country="US" currency="USD">3495.00</price><price country="NL" currency="EUR">3995.00</price><price country="BE" currency="EUR">3995.00</price><price country="IT" currency="EUR">3050.00</price><price country="SI" currency="EUR">3450.00</price><price country="IL" currency="ILS">14050.00</price><price country="GR" currency="EUR">3450.00</price><price country="MK" currency="EUR">3450.00</price><price country="HU" currency="EUR">3450.00</price><price country="DE" currency="EUR">3450.00</price><price country="CA" currency="CAD">4825.00</price></pricelist><miles/></course>