1
1

00:00:00,680  -->  00:00:02,430
<v ->Other WAN connections.</v>
2

2

00:00:02,430  -->  00:00:03,290
In this lesson,
3

3

00:00:03,290  -->  00:00:05,710
we're going to cover some other WAN connection types,
4

4

00:00:05,710  -->  00:00:08,700
specifically, SD-WAN and mGRE,
5

5

00:00:08,700  -->  00:00:09,780
because they're a bit different
6

6

00:00:09,780  -->  00:00:12,510
than the other WAN connections we already learned about.
7

7

00:00:12,510  -->  00:00:14,520
First, let's talk about SD-WAN
8

8

00:00:14,520  -->  00:00:17,020
or Software-Defined Wide Area Network.
9

9

00:00:17,020  -->  00:00:19,570
An SD-WAN is a virtual WAN architecture
10

10

00:00:19,570  -->  00:00:21,790
that allows enterprises to leverage any combination
11

11

00:00:21,790  -->  00:00:23,270
of transport services
12

12

00:00:23,270  -->  00:00:26,060
to securely connect users to their applications.
13

13

00:00:26,060  -->  00:00:29,400
And SD-WAN is essentially a software-based WAN architecture
14

14

00:00:29,400  -->  00:00:32,540
with all the control extracted from the underlying hardware.
15

15

00:00:32,540  -->  00:00:34,770
So instead of configuring specific infrastructure
16

16

00:00:34,770  -->  00:00:37,940
to handle application traffic, using something like MPLS,
17

17

00:00:37,940  -->  00:00:41,070
you can actually manage an SD-WAN entirely in software,
18

18

00:00:41,070  -->  00:00:44,530
plus layered over multiple types of network transport.
19

19

00:00:44,530  -->  00:00:45,780
This means we can really use
20

20

00:00:45,780  -->  00:00:48,130
any of the other WAN connections we may want to.
21

21

00:00:48,130  -->  00:00:51,270
Things like MPLS, a cellular connection, a microwave link,
22

22

00:00:51,270  -->  00:00:54,340
or a regular broadband internet service like a cable modem
23

23

00:00:54,340  -->  00:00:57,310
in order to create a virtual Wide Area Network architecture
24

24

00:00:57,310  -->  00:00:59,330
that we can then run our networks over.
25

25

00:00:59,330  -->  00:01:00,670
To create an SD-WAN,
26

26

00:01:00,670  -->  00:01:02,620
you can use a centralized control function
27

27

00:01:02,620  -->  00:01:04,820
to securely and intelligently redirect the traffic
28

28

00:01:04,820  -->  00:01:06,150
across the WAN.
29

29

00:01:06,150  -->  00:01:07,330
Our traditional WANs,
30

30

00:01:07,330  -->  00:01:08,710
which were never developed with the idea
31

31

00:01:08,710  -->  00:01:11,430
of integrating cloud services into our enterprise networks,
32

32

00:01:11,430  -->  00:01:12,520
can't do this.
33

33

00:01:12,520  -->  00:01:15,780
Instead, SD-WANs enabled cloud-first enterprises
34

34

00:01:15,780  -->  00:01:19,350
to deliver amazing quality experiences for their users.
35

35

00:01:19,350  -->  00:01:21,660
Let's consider a company that has several branch offices
36

36

00:01:21,660  -->  00:01:23,510
and one headquarters location.
37

37

00:01:23,510  -->  00:01:25,410
In our traditional WAn architectures,
38

38

00:01:25,410  -->  00:01:27,410
each branch office would likely be connected
39

39

00:01:27,410  -->  00:01:30,420
back to the central office using a star topology.
40

40

00:01:30,420  -->  00:01:31,540
This would allow the headquarters
41

41

00:01:31,540  -->  00:01:33,740
to conduct advanced security on that traffic,
42

42

00:01:33,740  -->  00:01:36,230
as it went from the branch offices to the headquarters,
43

43

00:01:36,230  -->  00:01:37,910
and then out to the Internet.
44

44

00:01:37,910  -->  00:01:39,620
This is great for security, sure,
45

45

00:01:39,620  -->  00:01:41,680
but it really slows down the entire process
46

46

00:01:41,680  -->  00:01:43,760
for the end users at those branch offices
47

47

00:01:43,760  -->  00:01:47,160
and results in a poor user experience and lost productivity.
48

48

00:01:47,160  -->  00:01:49,370
Now, unlike traditional architectures,
49

49

00:01:49,370  -->  00:01:51,780
SD-WANs can solve this by using intelligence
50

50

00:01:51,780  -->  00:01:53,330
to identify the network applications
51

51

00:01:53,330  -->  00:01:54,960
being used by the end users
52

52

00:01:54,960  -->  00:01:58,440
and routing that data across the WAN to the right places.
53

53

00:01:58,440  -->  00:01:59,740
This allows your WAN environment
54

54

00:01:59,740  -->  00:02:01,520
to be more dynamic and efficient
55

55

00:02:01,520  -->  00:02:04,020
while providing improvements in visibility, performance,
56

56

00:02:04,020  -->  00:02:06,960
and manageability of an enterprise WAN architecture
57

57

00:02:06,960  -->  00:02:09,040
from a single centralized point.
58

58

00:02:09,040  -->  00:02:10,990
Now, for the Network+ exam,
59

59

00:02:10,990  -->  00:02:13,127
you don't need to know how to configure an SD-WAN,
60

60

00:02:13,127  -->  00:02:15,820
but you do need to know when we might use it.
61

61

00:02:15,820  -->  00:02:18,200
So if you're working at a large enterprise network
62

62

00:02:18,200  -->  00:02:19,690
and you have lots of branch offices
63

63

00:02:19,690  -->  00:02:21,970
and they're trying to move more and more into the cloud
64

64

00:02:21,970  -->  00:02:24,800
using things IaaS and PaaS and SaaS,
65

65

00:02:24,800  -->  00:02:26,960
then you may need to use an SD-WAN
66

66

00:02:26,960  -->  00:02:28,960
to increase the performance for your end users
67

67

00:02:28,960  -->  00:02:30,530
and reduce bottlenecks that were caused
68

68

00:02:30,530  -->  00:02:33,280
by your traditional centralized WAN architecture.
69

69

00:02:33,280  -->  00:02:34,940
Now, the second type of WAN connection
70

70

00:02:34,940  -->  00:02:36,460
we need to discuss in this lesson
71

71

00:02:36,460  -->  00:02:40,670
is mGRE or Multipoint Generic Routing Encapsulation.
72

72

00:02:40,670  -->  00:02:43,760
mGRE is a protocol that can be used to enable one node
73

73

00:02:43,760  -->  00:02:45,700
to communicate with many other nodes,
74

74

00:02:45,700  -->  00:02:48,560
essentially creating a point-to-multipoint network.
75

75

00:02:48,560  -->  00:02:51,120
So, where might you use mGRE?
76

76

00:02:51,120  -->  00:02:52,760
Well, you could use mGRE
77

77

00:02:52,760  -->  00:02:54,450
on your router at your headquarters,
78

78

00:02:54,450  -->  00:02:56,860
and then you could support multiple other points
79

79

00:02:56,860  -->  00:02:59,800
such as your branch offices connecting back to it.
80

80

00:02:59,800  -->  00:03:01,730
With the older Generic Routing Encapsulation
81

81

00:03:01,730  -->  00:03:03,150
or GRE protocols,
82

82

00:03:03,150  -->  00:03:05,050
you are limited to point-to-point connections,
83

83

00:03:05,050  -->  00:03:08,090
but with mGRE, you can do point-to-multipoint.
84

84

00:03:08,090  -->  00:03:09,860
With those older GRE protocols,
85

85

00:03:09,860  -->  00:03:12,080
we would basically use GRE to create a tunnel
86

86

00:03:12,080  -->  00:03:15,560
and then create an IPSec tunnel within it to create a VPN
87

87

00:03:15,560  -->  00:03:17,870
by having a dedicated router at the branch site
88

88

00:03:17,870  -->  00:03:20,230
and another dedicated router at the headquarters.
89

89

00:03:20,230  -->  00:03:21,810
But with mGRE,
90

90

00:03:21,810  -->  00:03:23,830
we can instead have a single larger router
91

91

00:03:23,830  -->  00:03:24,930
at our headquarters
92

92

00:03:24,930  -->  00:03:27,680
that can support sending data from a single central router
93

93

00:03:27,680  -->  00:03:30,610
to all the multiple branch sites at one time.
94

94

00:03:30,610  -->  00:03:33,790
If you're going to use mGRE to sub this type of WAN connection,
95

95

00:03:33,790  -->  00:03:36,660
it's usually going to be combined with DMVPN
96

96

00:03:36,660  -->  00:03:39,480
or the Dynamic Multipoint VPN protocol.
97

97

00:03:39,480  -->  00:03:41,320
This will give you better security.
98

98

00:03:41,320  -->  00:03:43,790
This also allows you to create a dynamic VPN network
99

99

00:03:43,790  -->  00:03:45,890
with multiple sites without having to pre-configure
100

100

00:03:45,890  -->  00:03:47,510
the tunnel endpoint statically
101

101

00:03:47,510  -->  00:03:49,490
like you would with a traditional VPN.
102

102

00:03:49,490  -->  00:03:50,820
Again, for the exam,
103

103

00:03:50,820  -->  00:03:53,400
it's just important to know what mGRE is
104

104

00:03:53,400  -->  00:03:54,500
and what it's used for.
105

105

00:03:54,500  -->  00:03:57,800
So, remember, mGRE is used to create tunnels
106

106

00:03:57,800  -->  00:03:59,740
from one node to multiple nodes
107

107

00:03:59,740  -->  00:04:01,610
and can be used as a form of WAN connection
108

108

00:04:01,610  -->  00:04:02,730
within your network.
109

109

00:04:02,730  -->  00:04:04,030
It's most often going to be used
110

110

00:04:04,030  -->  00:04:06,960
with Dynamic Multipoint VPN or DMVPN
111

111

00:04:06,960  -->  00:04:09,890
for enterprise networks with multiple smaller branch sites
112

112

00:04:09,890  -->  00:04:12,160
that need to connect back to a centralized site.
113

113

00:04:12,160  -->  00:04:14,280
It's a more traditional type of WAN architecture
114

114

00:04:14,280  -->  00:04:16,093
than using something like SD-WAN.
