Cisco SD-WAN vEdge Onboarding

Hello @ReneMolenaar ,

I’m building the lab with version 19.2 but when I tried to add the vEdge to vManage it didn’t show up even when I made the steps several times in case if I forget something.

Hello @mohamedtarik8 ,

This is a good document to start with:

It includes a lot of troubleshooting steps and show commands to figure out what is going wrong.

Rene

I’m having the same trouble as Justin D

After I go to request vedge-cloud activate, my vedge device never gets added and when I do show control local-properties my certificate status changes to “not-installed”

Edit: my bad. If you come by this, my issue was that somehow I typed my sp-organization-name wrong when I set it. I changed it to what it should be and it worked

Hello Kyle

Thanks for letting us know of your specific issue as well as the solution! It’s always helpful when users include their solutions like that, it’s much appreciated!

I hope this has been helpful!

Laz

Hello dear
I want to ask
In the vedge you configure one ip route to ISP 1

ip route 10.1.0.0/24 10.65.91.100

What if this isp failed
The vedge will be unreachable from vmanage
Correct

Hello Aysar

Yes, that is correct. If the ISP failed, the connection of the vEdge to the vManage would also fail.

For this reason, Cisco recommends a high-availability network architecture for vEdge routers. This requires a specific approach, which is outlined in detail in the following Cisco configuration documentation:

I hope this has been helpful!

Laz

Hi Rene,

As shown below I am trying to add vEdge router to vManage but unsuccessful as on vEdge no serial number is shown. Any idea why and is there a work around?

viptela 19.2.2

vEdge-10 login: admin
Password:
Welcome to Viptela CLI
admin connected from 127.0.0.1 using console on vEdge-10
vEdge-10#
vEdge-10# show certificate serial
Certificate not yet installed ... giving up.
Chassis number: 262dceb9-f7b1-4c27-b00f-30fb399c49db serial number:

vManage# request vedge add chassis-num 262dceb9-f7b1-4c27-b00f-30fb399c49db serial-num
Value for 'serial-num' (<Serial number in board ID public certificate>):

Hello Kenneth

A vEdge device has a serial number that is included in the device’s certificate. If the device doesn’t have a certificate, a serial number will not appear in the output. Try issuing the show control local-properties command on the vEdge device to see the details of the certificate states. In the output you should see something like this:

!<-- output omitted -->
chassis-num/unique-id 867391ba-8fa4-3c5b-93ed-cb406e15c1b0
serial-num No certificate installed
subject-serial-num N/A
token bb1e1f89468f4c65a5f34450ee61054b
!<-- output omitted -->

Notice that the result for serial-num is “No certificate installed

Ensure that you’ve installed the certificate correctly in the previous steps and check out the results of the above command. For more information about vEdge serial numbers, take a look at this Cisco documentation:

I hope this has been helpful!

Laz

Hi Rena,

I don’t have a any SDWAN license.

Want to practice SDWAN scenarios in EVE-NG LAB.

How should I add Vedge or Cedge in Vmang in the EVE-NG Lab for practice purpose?

Hi Rena,

Need your support here

Hello Pratik

As stated in the lesson, you can create licenses using the following lesson:

Specifically, it states:

If you want to add vEdge or cEdge licenses to your Cisco SD-WAN network, you’ll need some device “licenses”. In Cisco SD-WAN versions before 20.x, it was possible to skip this. If you build a lab using version 20.X or later, you need to create these licenses on the Cisco.com website and import them on your vManage controller. If you use version 20.x or later, follow this lesson and I’ll explain how to create these licenses.

Follow the rest of the lesson as stated and you can create what you need to practice your SD-WAN scenarios on EVE-NG.

I hope this has been helpful!

Laz

Thanks Rena.

I tried to create it but the smart license is not available on my id.

I created it, but it is still not visible and has not been approved by Cisco.

Hello Pratik

Anyone can create a smart account without any prerequisites. You can do this by going to the following Cisco documentation:

Once you create it, you can then go on to the process described in the lesson. Let us know how you get along!

I hope this has been helpful!

Laz

Hi rena,

I’m getting attached error while creating a license in the cisco portal to practice SD-WAN Lab in the EVE-NG Platform

Hello Pratik

Hmm, that’s interesting. I did some research and have found that a small number of others are having similar problems:

Unfortunately, there are no reported solutions.

Now having done this research, another thing that comes to mind is that Cisco has certain export restrictions on some of its products due to their advanced features or capabilities that may have potential military or security applications. These restrictions are enforced by governments to control the export of such technology to certain countries or users.

In any case, I will let Rene know about this one and get back to you…

Laz

Can you please share alternate solution or help to export 10 licence with your help.

Hello Pratik

Withoutht knowing the specific reason that the license is considered “Export Restricted” for your account, it’s difficult to share a workaround. After consulting with Rene, the only thing that I can suggest is that it may be country related. You can try to connect via a VPN from a different country, and attempt to create a new CCO account through the VPN. Then try to download the license.

I hope this has been helpful!

Laz

Hello NWL team,

I’d like your support to understand what’sd happening on my lab, I did all steps until create the templates for vEdge1 and push it to the device, everything worked fine, but when I restarted my lab the certificate shows as installed on vManage but vEdge1 is unreachable (underlay is OK) , but on vEdge1 I have the following information:

chassis-num/unique-id             f4bd3bdb-94f2-4b5e-a823-955349377648
serial-num                        No certificate installed
subject-serial-num                N/A
token                             Invalid

vManage Info:
vEdge Cloud f4bd3bdb-94f2-4b5e-a823-955349377648 vEdge1 172.16.1.1 39873***

The vEdge2 that I still didn’t configure with template is working fine.

Hello Roger

Hmm, not sure why a restart of the topology would cause such behavior. It is likely that the problem has to do with the template that was used for vEdge1, since vEdge2 is unaffected, and wasn’t configured with the template.

What action do you need to take to resolve the issue? If you reapply the template, does that resolve the issue or do you need to reinstall the certificate? If not, do you have to create a new template to get it to work? The actual solution will give us insight into where the problem lies.

The issue may have to do with the EVE-NG platform, and not the actual Cisco implementation, however, you must determine what troubleshooting steps will resolve the issue so that we can further investigate the reason for the problem. Let us know how you get a long.

I hope this has been helpful!

Laz

With reference to your configuration vEdge has 2 links one to biz-internet and one to public-internet and both color is configured on the 2 interfaces. Any reason why show ip route only display color ‘biz-internet’ and ‘default’ instead of biz-internet’ and ‘public-internet’?
Also since there are 2 links why is there only a route to next hop 10.65.91.100?
ip route 10.1.0.0/24 10.65.91.100
If another static route is add with next hop of 10.65.92.100, how would vEdge prioritize the routes?
ip route 10.1.0.0/24 10.65.92.100