Professional Documents
Culture Documents
5.19.20 - Q and A For Cisco Automates and Secures The Edge
5.19.20 - Q and A For Cisco Automates and Secures The Edge
5.19.20 - Q and A For Cisco Automates and Secures The Edge
________________________________________________________________
________________________________________________________________
Q: Any plans about providing the ability to change BFD dscp value, example for UC traffic circuits?
A: For the most traffic is marked with the appropriate DSCP values. Support for changing the DSCP
values for BFD is under consideration.
________________________________________________________________
A: PIM-SM, SSM.
________________________________________________________________
Q: When upgrading an existing end point to 17.2 will it boot in autonomous mode after the upgrade
even if it is currently being managed by a controller?
A: The default mode is autonomous mode. You can switch the controller mode.
________________________________________________________________
Q: What is the best way to size the replicator in multicast in term of performance and platforms
needed?
A: Depends on the amount of multocats stream and receivers... recommend head-end nodes like ASR1K
or VEdge 5K.
________________________________________________________________
A: CVD (Cisco Validated design) document will be published soon. Team is working on it.
________________________________________________________________
Q: With rls 17.2, can we have the SRST running on the same router?
________________________________________________________________
Q: What is the timeline for 17.3 as voice gateway without T1/E1 support doesn't make sense.
________________________________________________________________
A: Yes the same SD-WAN router will deliver CUBE functionality. CUBE is scoped for 2CY2021.
________________________________________________________________
________________________________________________________________
A: SIP-FXO, SIP-FXS, SIP-T1 are the flows that will be supported till CUBE comes into play.
________________________________________________________________
A: Is the question on naming for extended maintenance releases? The naming convention will stay same
for standard and maintenance releases.
________________________________________________________________
________________________________________________________________
Q: If we have internet only through head office, do we need to integrate branch sd wan routers to
umbrella? How is the license goes?
A: Branch routers do not need to be integrated to Umbrella in that case. You can make the connection
just head office if you want to use Umbrella still. No change in Umbrella licensing (it is done per seat).
________________________________________________________________
Q: Related to Umbrella / SIG - Can you explain more of what the Zscaler L7 Healthcheck is?
A: This utilizes an HTTP layer connecting test instead of IPsec/IKE dead peer detection to determine if
the tunnel is active and healthy. The L7 option provides a higher fidelity indicator of system health, and
can detect changes to status faster than DPD. Basically its IPSLA to Zscaler. Umbrella is working with
Viptela on getting this supported. Target is July with 17.3.
________________________________________________________________
A: Yes VPN0.
________________________________________________________________
A: DNA Premier includes SIG. DNA-Advantage gives you up to DNS Monitoring. DNA-Premier license
gives you SIG Essentials.
________________________________________________________________
A: Some L7 features are included in DNA-P: Hostname filtering, URL filtering, all types of HTTP
inspection. The only thing not included is the L7 AVC for non-HTTP apps. This is available as an add-on.
________________________________________________________________
Q: Did I miss that the Umbrella integration will become available in 17.3?
________________________________________________________________
________________________________________________________________
Q: Can we have umbrella DNS security only without SIG on the edge devices?
A: Absolutely. This can be done with a DNS Essentials or DNS Advantage license. The DNS security
options are also included in the SIG license if you want to have some devices with SIG and some with
just DNS.
________________________________________________________________
________________________________________________________________
________________________________________________________________
Q: What are the features which lack if we use only dna-essentials regarding umbrella compared to dna
premier?
A: DNA-E, doesn’t include SIG and is a DNS monitor only. You could purchase DNS Essentials to get
blocking protection.
________________________________________________________________
A: Could you be more specific? There is no connector or a way to manage both, but you could create an
IPSEC tunnel between them. Not sure I get the question.
________________________________________________________________
Q: So DNA-E gives you DNS and DNA-P gives you everything else (full SIG), correct? Does DNA-A provide
anything in-between?
A: DNS monitoring only in DNA/e, in DNA/a you get a shadow IT app. Neither provide blocking
(protection).
________________________________________________________________
A: Yes, the updates are valid for both ViptelaOS 20.1 and IOS XE 17.2.
________________________________________________________________
Q: Does ISR 1100 replace Vedge 1000 platform since you showing arrow?
________________________________________________________________
A: https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/branch-wan-
edge.html
________________________________________________________________
________________________________________________________________
Q: When Umbrella SIG supports L7 App firewall - will DNA Primer licenses be able to use the L7 umbrella
capabilities at with nu upcharge of $$?
A: When DNA-Premier license is chosen, it will be a single license SKU. No change in DNA-P price today,
there will be seat limitations (Umbrella seats) beyond certain bandwidth tiers for which you can buy
add-on licenses.
________________________________________________________________
A: CUBE connector is an option to support CUBE which does not need Transcoding.
________________________________________________________________