CCDE SD-WAN Design Part 22 — Enterprise Migration Strategy, Cloud Controllers, Hybrid WAN, and Make-Before-Break Deployment
- How enterprise SD-WAN migrations are planned
- Why cloud-hosted controllers simplify SD-WAN onboarding
- Understanding make-before-break migration methodology
- How hybrid WAN architecture works
- How BGP and OMP interact during migration
- How VRRP is used during gradual cutovers
- How MPLS and Internet coexist during transition
- How to minimize downtime in large enterprise migrations
- Mathematical analysis of convergence and migration risk
- Real-world enterprise deployment sequencing logic
Table of Contents
- 1. Understanding the Business Requirement
- 2. Why Cloud SD-WAN Controllers Were Chosen
- 3. Hybrid WAN Enterprise Architecture
- 4. The Philosophy of Enterprise Migration
- 5. Correct Migration Sequence
- 6. Step A — Order Circuits and Hardware
- 7. Step B — Configure Cloud Controllers and Firewalls
- 8. Step C — Install SD-WAN Edge Routers in DCs
- 9. Step D — Configure Inter-DC iBGP and OMP Redistribution
- 10. Step E — Install Store SD-WAN Edge Routers
- 11. Step F — Build Internet SD-WAN Tunnels
- 12. Step G — Migrate Independent Stores First
- 13. Step H — Shut Down Independent MPLS Links
- 14. Step I — Redirect Jacobs and Toolmate Stores
- 15. Step J — Add MPLS-Based SD-WAN Tunnels
- 16. Step K — Remove Redundant MPLS Links
- 17. Step L — Final MPLS Decommissioning
- 18. Mathematical Analysis of Migration Stability
- 19. Configuration and Verification Examples
- 20. Machine Learning Analogy for Migration Optimization
- 21. Related Articles
- 22. Final Conclusion
1. Understanding the Business Requirement
Jacobs is performing a full enterprise WAN transformation.
The organization is migrating:
- Legacy MPLS WAN
- Dual-MPLS branch architecture
- Traditional branch routing
- Manual provisioning
toward:
- Cloud-managed SD-WAN
- Hybrid WAN transport
- Internet + MPLS coexistence
- Automated onboarding
- Controller-driven orchestration
The business explicitly requires:
- Minimal downtime
- Validated service before production migration
- No unnecessary outages
- Fast rollback capability
2. Why Cloud SD-WAN Controllers Were Chosen
James Medina selected cloud-hosted SD-WAN controllers for several reasons.
Main Benefits
| Feature | Benefit |
|---|---|
| Cloud Resilience | No need for local controller HA |
| Zero Touch Provisioning | Automatic onboarding |
| Centralized Certificates | Simplifies PKI management |
| Controller Automation | Template-driven deployment |
| Reduced Operational Complexity | Less burden on networking team |
Cloud Controller Components
| Controller | Purpose |
|---|---|
| vManage | Management plane |
| vSmart | Control plane |
| vBond | Orchestration plane |
3. Hybrid WAN Enterprise Architecture
+----------------------+
| SD-WAN Cloud |
| Controllers |
+----------+-----------+
|
------------------------------------------------
| |
| |
+---------+----------+ +---------------+---------+
| Jacobs DC | | Toolmate DC |
| SD-WAN + MPLS | | SD-WAN + MPLS |
+----------+---------+ +-------------+-----------+
| |
|-------------- DCI iBGP ---------------------|
|
-----------------------------------------------------------------------
| | |
| | |
| | |
+-----------+ +--------------+ +----------------+
| Jacobs | | Independent | | Toolmate |
| Branches | | Branches | | Branches |
+-----------+ +--------------+ +----------------+
4. The Philosophy of Enterprise Migration
The Core Principle
Never remove the existing working path until the new path is:
- Installed
- Validated
- Tested
- Operational
This principle dominates:
- CCDE design
- Enterprise migration strategy
- Data center migrations
- Cloud migrations
- SD-WAN onboarding
5. Correct Migration Sequence
Final Ordered Sequence
| Step | Activity |
|---|---|
| A | Order circuits and hardware |
| B | Configure cloud controllers and firewalls |
| C | Install SD-WAN edge routers in DCs |
| D | Configure inter-DC iBGP and OMP redistribution |
| E | Install SD-WAN edge routers at stores |
| F | Establish SD-WAN control-plane tunnels |
| G | Migrate independent stores first |
| H | Shut down independent MPLS links |
| I | Redirect Jacobs/Toolmate stores to Internet SD-WAN |
| J | Add MPLS-based SD-WAN tunnels |
| K | Remove redundant MPLS links |
| L | Final MPLS decommissioning |
6. Step A — Order Circuits and Hardware
This must always happen first.
Why?
- Lead times are long
- Hardware shipping takes time
- Carrier provisioning is slow
- 5G activation requires coordination
Enterprise Reality
Large enterprises may order:
- Hundreds of routers
- Hundreds of SIM cards
- Multiple MPLS modifications
- Cloud licenses
7. Step B — Configure Cloud Controllers and Firewalls
Why This Happens Early
SD-WAN edge routers require:
- Controller reachability
- Certificate validation
- Template download
- TLOC configuration
- OMP participation
Therefore controllers must already be operational.
Firewall Flows Required
| Traffic | Purpose |
|---|---|
| Edge → vBond | Orchestration |
| Edge → vSmart | Control plane |
| Edge → vManage | Management |
| IPSec DTLS/TLS | Secure overlay tunnels |
8. Step C — Install SD-WAN Edge Routers in DCs
The DC deployment occurs in parallel with the existing WAN.
This is important because:
- No downtime occurs
- Testing becomes possible
- Overlay can form gradually
eBGP Between LAN and SD-WAN Edge
The DC LAN advertises:
- Server prefixes
- DMZ prefixes
- Application networks
toward SD-WAN fabric.
9. Step D — Configure Inter-DC iBGP and OMP Redistribution
Why This Happens After Step C
Because:
- BGP neighbors must already exist
- SD-WAN routers must already be reachable
- OMP routes must already be available
Understanding OMP
OMP = Overlay Management Protocol
It is Cisco SD-WAN’s control-plane routing protocol.
OMP distributes:
- TLOCs
- Service routes
- VPN routes
- Policy information
OMP to BGP Redistribution
The SD-WAN fabric learns:
Store Prefixes
and redistributes them into:
Traditional BGP
This allows coexistence between:
- Legacy WAN
- SD-WAN overlay
10. Step E — Install Store SD-WAN Edge Routers
The routers are connected:
- In parallel
- Without traffic cutover
- Without becoming active gateway
VRRP Strategy
The new SD-WAN edge receives:
LOW VRRP PRIORITY
This prevents traffic blackholing.
Example VRRP Priorities
| Router | Priority |
|---|---|
| Existing MPLS Router | 150 |
| Backup MPLS Router | 120 |
| New SD-WAN Edge | 50 |
11. Step F — Build Internet SD-WAN Tunnels
Now the control plane is formed.
Secure tunnels are created using:
- IPSec
- DTLS
- TLS
Overlay Tunnel Formula
If:
$$ N = Number\ of\ WAN\ edges $$
Then full mesh tunnel count becomes:
$$ T = \frac{N(N-1)}{2} $$
As enterprises scale:
Tunnel count grows exponentially.
12. Step G — Migrate Independent Stores First
This is extremely important.
Why Independent Stores First?
- Lower business criticality
- Short downtime acceptable
- Excellent pilot environment
- Allows production validation
Always migrate the lowest-risk environment first.
Traffic Migration
Traffic steering changes from:
Store → MPLS
to:
Store → SD-WAN Internet Overlay
13. Step H — Shut Down Independent MPLS Links
This happens ONLY after:
- Validation
- Testing
- Stability confirmation
Notice:
Decommissioning is always delayed.
14. Step I — Redirect Jacobs and Toolmate Stores
Now production-critical sites migrate.
Why Safe Now?
Because:
- Controllers are validated
- Internet overlay works
- Independent stores succeeded
- Rollback procedures exist
15. Step J — Add MPLS-Based SD-WAN Tunnels
Now SD-WAN becomes:
- Hybrid WAN
using:
- Internet transport
- MPLS transport
Why This Happens Late
During insertion:
- Existing MPLS CE topology changes
- Physical rewiring occurs
- Temporary risk exists
Therefore:
- Internet SD-WAN path must already work first
16. Step K — Remove Redundant MPLS Links
Now:
- Internet SD-WAN is stable
- MPLS SD-WAN is stable
- Dual transport exists
One MPLS link becomes unnecessary.
17. Step L — Final MPLS Decommissioning
This is ALWAYS the final step.
Enterprise migrations commonly wait:
- 30 days
- 60 days
- 90 days
before carrier circuit cancellation.
Because rollback capability is critical during stabilization.
18. Mathematical Analysis of Migration Stability
Migration Risk Formula
Let:
$$ R = Risk $$
$$ D = Downtime $$
$$ B = Backup\ paths $$
Then:
$$ R \propto \frac{D}{B} $$
Increasing backup paths reduces migration risk.
Availability Formula
If:
$$ A_1 = Internet\ Availability $$
$$ A_2 = MPLS\ Availability $$
Combined hybrid WAN availability:
$$ A = 1 - (1-A_1)(1-A_2) $$
This demonstrates why hybrid WAN improves resilience.
Convergence Reduction
Traditional migration:
$$ T = Detection + Recalculation + Installation $$
Prebuilt SD-WAN overlay:
$$ T = Detection + Installation $$
Convergence becomes dramatically faster.
19. Configuration and Verification Examples
Sample SD-WAN Edge Configuration
system
host-name Branch1
site-id 101
organization-name Jacobs
vbond cloud.jacobs.com
vpn 0
interface ge0/0
ip address dhcp
tunnel-interface
encapsulation ipsec
Sample BGP Configuration
router bgp 65050
neighbor 10.1.1.1 remote-as 65100
address-family ipv4
network 10.10.10.0 mask 255.255.255.0
Verify OMP Routes
show omp routes
Sample Output
OMP Routes: 10.10.10.0/24 TLOC: biz-internet Preference: 250
Verify Control Connections
show control connections
Sample Output
PEER TYPE SITE ID DOMAIN ID PEER PRIVATE IP vBond 0 1 52.12.11.10 vSmart 0 1 52.12.11.11 vManage 0 1 52.12.11.12
20. Machine Learning Analogy for Migration Optimization
Modern SD-WAN increasingly resembles machine learning optimization systems.
The controller evaluates:
- Latency
- Loss
- Jitter
- Historical trends
- Application behavior
This is similar to predictive optimization models in AI.
Cost Function Analogy
SD-WAN path selection:
$$ Cost = \alpha L + \beta J + \gamma P $$
Where:
- $L$ = Latency
- $J$ = Jitter
- $P$ = Packet Loss
Useful AI and Data Science Reading
- How Machine Learning Models Learn
- Real World Examples of Machine Learning
- Handling Imbalanced Datasets in Machine Learning
- Softmax vs Probability
- Task2Vec and Optimization
- Mastering EIGRP Route Metrics with Mathematics
21. Related Articles
- CCDE Enterprise Case Study Part 1
- CCDE Enterprise Case Study Part 2
- CCDE Enterprise Case Study Part 3
- CCDE MPLS Architecture Part 4
- CCDE DMVPN Architecture
- CCDE SD-WAN Architecture Explained
- CCDE Best WAN Design
- CCDE Internet SD-WAN Design
- CCDE 5G DIA SD-WAN Design
- CCDE Toolmate SD-WAN Design
- CCDE Building Enterprise SD-WAN
- CCDE Branch SD-WAN Design
- CCDE Routing Loop Prevention
- CCDE BGP ASN Design
- CCDE Optimal SD-WAN Routing
- CCDE SD-WAN Design Part 23: Application-Aware Routing, QoS, SLA Policies, and MPLS vs 5G Optimization
22. Final Conclusion
This migration question is not testing deep SD-WAN product knowledge.
Instead, it is testing:
- Migration methodology
- Risk reduction strategy
- Routing dependencies
- Operational sequencing
- Enterprise change management
Enterprise migrations should ALWAYS follow:
MAKE BEFORE BREAK
The new infrastructure must:
- Exist
- Be validated
- Be stable
- Be tested
before removing legacy infrastructure.
The migration sequence used by Jacobs is a textbook enterprise SD-WAN rollout model because it:
- Minimizes downtime
- Provides rollback capability
- Validates SD-WAN gradually
- Protects production business traffic
- Reduces operational risk
No comments:
Post a Comment