Enterprise SD-WAN Migration & Zero Trust Security Architecture
Simulasi Transformasi Digital Jaringan Ritel Multi-Cabang (Expert / Specialist - 240 Menit)
Nilai Evaluasi Lab
0 / 100
Interaksi Topologi Jaringan (Klik Perangkat untuk Konfigurasi)
Reset Lab
!
SD-WAN Controllers
vManage / vSmart / vBond
MPLS Cloud
Private Transport
Public Internet
Direct Internet Access
!
vEdge HQ Cluster (2 Unit)
Dual WAN (MPLS + Inet)
!
vEdge Cabang A & B
ZBF & URL Filter: Off
L3 Core SW HQ
Stacking / VRRP
!
Access Switches Cabang
802.1X / ZTNA: Off
ZTNA & RADIUS/MFA Server
10.10.10.50
Terminal POS / Kasir
VLAN 10 (Kasir)
Rogue Laptop Test
Unauthenticated
Rubrik Penilaian Modul (Total 100 Point)
Modul 1: SD-WAN Controller & OMP Setup
25 Poin
Autentikasi sertifikat vManage/vSmart valid dan OMP peering terjalin di SD-WAN Fabric.
Modul 2: Dynamic Path & AAR Policy
20 Poin
AAR memprioritaskan POS via MPLS, Web via DIA, serta failover ke IPsec Internet jika loss > 2%.
Modul 3: ZTNA & 802.1X Port Security
25 Poin
802.1X RADIUS aktif di access switch dan Micro-Segmentation mengisolasi VLAN POS secara total.
Modul 4: ZBF & Cloud Security Integration
15 Poin
Zone-Based Firewall membatasi POS HANYA ke port HTTPS (443) Payment Gateway & URL Filter aktif.
Modul 5: Fabric Outage & ZTNA Breach Challenge
15 Poin
Data plane bertahan saat vSmart down (Graceful Restart) & Rogue Device terblokir (Err-Disable).
Live Security Log & Audit Terminal
sdwan-fabric-console v18.4
Uji SLA AAR Failover
Toggle vSmart Controller
Simulasi Rogue Device Attack (ZTNA Breach Test)
Modul 1: SD-WAN Controller Onboarding
×
Atur parameter dasar Control Plane untuk mengaktifkan Overlay Management Protocol (OMP).
vManage / vSmart Enterprise Root CA Certificate
Unsigned / Invalid Certificate
Installed & Verified (Cisco Enterprise CA)
Overlay Management Protocol (OMP) Status
Disabled
Enabled & Peering Active
Modul 2: Dynamic Path Selection & AAR Policy
×
Konfigurasi Application-Aware Routing Policy untuk memisahkan trafik POS Kasir dan Trafik Internet (DIA).
Jalur Utama Transaksi POS Kasir
Public Internet (High Latency)
MPLS Dedicated Transport (Low Latency)
AAR SLA Failover Threshold (Packet Loss Threshold)
Packet Loss > 5%
Packet Loss > 2% (Target Expert SLA)
Direct Internet Access (DIA) untuk Web / O365
Disabled (Backhaul via HQ)
Enabled (Local Breakout via vEdge Branch)
Modul 3: ZTNA & 802.1X Port Security
×
Terapkan prinsip Never Trust, Always Verify pada switch port jaringan cabang.
802.1X Port Authentication (RADIUS Integration)
Disabled (Open Port Security)
Enabled (RADIUS MFA Enforcement)
Micro-Segmentation Policy (Isolation VLAN Kasir)
Disabled (POS Boleh Akses Guest/Admin)
Enabled (POS Terisolasi Penuh dari Guest & Admin)
Modul 4: Zone-Based Firewall & Cloud Security
×
Integrasikan proteksi keamanan perimeter pada vEdge Cabang.
vEdge Branch Zone-Based Firewall (ZBF)
Allow All Traffic
Inside (POS) -> Outside: HTTPS 443 Only (Deny Inbound)
URL Filtering & DNS Security Engine
Disabled
Enabled (Block Malicious / High Risk Sites)