Security in Cisco Catalyst SD-WAN is too important to leave out of the foundation volume of this book. At the same time, the security features are not ideal for a pure CLI-based lab. They are designed to be configured from the graphical interface, either through UX1.0 (Device Templates and Security Policy) or UX2.0 (Configuration Groups and Policy Groups/NGFW).
For that reason, I changed the configuration method of cEdge-3 behind the scenes from CLI to a Configuration Group. Everything else is still managed via CLI. However, in Volume 1, we do not cover GUI-based configuration methods such as Configuration Groups (UX 2.0) or Device Templates (UX 1.0). Those topics are introduced conceptually in Volume 2 and then explained in more detail there. If you need help creating and applying a Configuration Group to cEdge-3, you can refer to the online version of the book or to the first chapter of Volume 2.
Also notice that the security configuration model has changed quite a lot in almost every MD software release (20.9 / 20.12 / 20.15 / 20.18 / 26.1, etc.). In recent major ones, Cisco is clearly moving toward a more unified security model, where firewall rules are configured in a more consistent way across different platforms, such as Catalyst SD-WAN, Cisco Secure Firewall, and other security products. The big goal is reusability. Instead of building isolated security policies directly tied to individual devices, Cisco wants security objects, profiles, and policy components to be reusable. This makes the configuration easier to scale and easier to maintain.
Digital Book Access
For now, the digital version of this book is available only to active subscribers and readers who own a paperback copy.
The ability to buy the digital copy directly is coming soon.
- Subscribers can access the full digital version as part of their membership.
- Paperback owners can access the digital version using the instructions provided in the book.