Purpose and Functionality #
The Cisco SD-WAN (Viptela) solution can function as a Service Gateway (SG), offering a flexible and scalable method for connecting customer networks to cloud services. By utilizing vManage, SD-WAN routers can be provisioned with templates that automate secure connectivity between customer networks and their assigned cloud instances. This setup ensures seamless cloud access while enabling local internet breakout at each customer site, optimizing traffic flow and reducing latency for cloud-bound applications.
Key Features of Cisco SD-WAN as Service Gateway: #
-
Provisioning via vManage: #
- Configuration templates in vManage streamline deployment, enabling standardized setups across all SD-WAN routers.
- Each router is automatically configured to securely connect to the customer’s designated cloud instance.
- Local Internet Breakout:
- Leverages SD-WAN capabilities to allow direct internet access at customer locations.
- Enhances performance for internet-bound traffic while maintaining secure and reliable connectivity to the cloud service.
- Centralized Management and Monitoring:
- vManage serves as a centralized platform for managing and monitoring the SD-WAN infrastructure.
- Comprehensive statistics and telemetry data from all SD-WAN Service Gateways are collected via the vManage API, providing visibility into network performance and enabling proactive troubleshooting.
- Standard SG Features:
Cisco SD-WAN as a Service Gateway retains the following core capabilities:- Secure Tunneling:
- FlexVPN or SD-WAN-native IPsec connectivity for encrypted communication.
- Policy-Based Routing and Dynamic Segmentation:
- Supports SGT/SXP tunnels and SGT-to-IP mapping for secure, dynamic traffic segmentation.
- Compatibility:
- Works with both LAN and wireless LAN networks, ensuring adaptability across infrastructures.
- Redundancy Options:
- Includes hot standby for failover and load balancing for optimized performance.
- Instance Isolation:
- Implements VRF (Virtual Routing and Forwarding) for tenant isolation in multi-tenant environments or segmentation within enterprises.
- Secure Tunneling:
With Cisco SD-WAN (Viptela) as an SG, organizations gain a robust, scalable solution that integrates seamlessly into existing infrastructure while providing enhanced performance and secure connectivity to cloud services.

ServiceGateway Router Support Matrix #
The table below lists the Cisco router series that are verified and fully compatible with the SignIn ServiceGateway integration. The specified license levels are required to enable the features utilized by the integration.
| Router Series | Required License | Feature Utilization | Support Status |
|---|---|---|---|
| Cisco ISR 1100 Series | Security (SEC/K9) + AppX | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco ISR 4400 Series | Security (SEC/K9) + AppX | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8100 Series | DNA Essentials | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8200 Series | DNA Essentials | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8300 Series | DNA Essentials | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8400 Series | DNA Essentials | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8500 Series | DNA Essentials | Cisco TrustSec (CTS), ePBR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
Note #
-
Require Cisco IOS XE 17.6.8a or later.