{"id":35405,"date":"2023-05-15T19:33:33","date_gmt":"2023-05-15T19:33:33","guid":{"rendered":"https:\/\/zpesystems.com\/?p=35405"},"modified":"2024-08-12T11:33:27","modified_gmt":"2024-08-12T18:33:27","slug":"defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/","title":{"rendered":"Defusing Cisco SD-WAN Time-bomb requires out-of-band access"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.17.5&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; width=&#8221;100%&#8221; custom_padding=&#8221;0px||1px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; header_3_text_color=&#8221;#214C64&#8243; header_4_text_color=&#8221;#358AAF&#8221; global_colors_info=&#8221;{}&#8221;]Viptela SD-WAN devices are used at large enterprise branches all around the world.  The success of SD-WAN replaced dedicated service provider managed MPLS with customer managed boxes that used commodity internet connectivity giving more options and power to leadership and engineering.  It solved the single-point-of-failure issues with Internet connectivity and using overlay networking, created a secure WAN topology never thought possible with commodity Internet connectivity. The unsolved issue is the platform itself. Viptela SD-WAN vEdge devices like many others have a fatal flaw in built-in encryption and authentication. The issue reared its head on May 9th 2023.  The boxes shipped with a 10 year root certificate that was created in 2013.  The flaw, designed 10 years ago, is that the certificate is a single point of failure to ensure the platform can\u2019t be trusted to form encrypted connections any longer after the certificate expires. This flaw takes down the entire control plane of the platform which in turn takes down the entire dataplane for all user traffic.   [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">We are actively working to address an issue impacting a number of Viptela SD-WAN platforms. <img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/media\/FvxUke7WAAQV2vh?format=jpg&amp;name=medium\" \/><\/p>\n<p>\u2014 Cisco (@Cisco) <a href=\"https:\/\/twitter.com\/Cisco\/status\/1656294258779750401?ref_src=twsrc%5Etfw\">May 10, 2023<\/a>\n<\/p><\/blockquote>\n<p><script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;||||||||&#8221; link_font=&#8221;||||on||||&#8221; link_text_color=&#8221;#FFFFFF&#8221; background_color=&#8221;#214C64&#8243; custom_padding=&#8221;15px|10px|15px|10px|true|true&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/www.futuriom.com\/articles\/news\/cisco-viptela-customers-deal-with-sd-wan-time-bomb\/2023\/05\">Read the Futuriom article<em> &#8216;Cisco Viptela Customers Deal with SD-WAN &#8216;Time Bomb'&#8221;<\/em><\/a><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]Designing PKI certificate management into the platform during the development cycle would have ensured that this never happened. The platform QA team would then be alerted that the cert is about to expire and securely rotate it or simply build a new software patch with a new 10 year root certificate that pushes out the validity window.  These are common problems and do fall into cracks from time to time taking down branch networks and what IT teams need to do to fix it is even worse.  Today we see many companies calling emergency meeting for \u201cPKI lifecycle management\u201d [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><strong>The fix to this problem requires upgrade of the control software in the cloud or datacenter which is <em>not so bad<\/em>.<\/strong> To automate and properly secure the certificate on the platform the branch hardware also needs to be upgraded. This due to limitations for secure chips like a TPM (Trusted Platform Module) to correctly secure the supply chain of the platform.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]In the Viptela case, SD-WAN device in most customer environments was the only way to get into the branch then there is no way to upgrade it when its down.  Cisco website requires an out-of-band device to have been previously installed at remote locations.  If an out-of-band serial console device is not installed then the fix will require a costly truck roll at a rough cost of $1200\/site. This will not count the cost of downtime.  [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]ZPE systems has a cost calculator on the website that shows the cost of downtime for this Cisco outage for an organization with 400 branch locations is ~$5M USD.  This is the cost of truck rolls at $1200 each and cost of downtime for 8 hours at $1K\/hour.  <a href=\"https:\/\/zpesystems.com\/roi-calculator\/\">ZPE Systems&#8217; Cost of Downtime ROI Calculator<\/a>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]Many customers will suffer as it may not be possible to drive to 400 locations., This problem will take down many branches for at least a week.  Cisco Viptela was so successful with this product there are 1000\u2019s of customers that are impacted each with 100\u2019s of locations and there are not enough resources to fix this in a timely fashion.   [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>For this reason <span style=\"text-decoration: underline;\"><strong>Cisco requires out-of-band connectivity devices to recover from this issue<\/strong><\/span>. To be a completely touchless solution, the device should also be deliverable with Zero Touch Provisioning (ZTP) so that the device can be simply shipped in, and physically connected by onsite staff. In the Cisco article below you\u2019ll see the note that the only way to recovery from this issue is to have out-of-band connectivity to service as a dedicated control plane to get back into your remote networks and remediate quickly and automatically.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><strong>Note Cisco caution below:<\/strong><br \/><span style=\"text-decoration: underline;\">Caution: To recover these devices, out-of-band access is required.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/Cisco.png&#8221; alt=&#8221;Cisco&#8221; title_text=&#8221;Cisco&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;||||||||&#8221; text_font_size=&#8221;12px&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Source: https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/routers\/sd-wan\/220448-identify-vedge-certificate-expired-on-ma.html<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;||||||||&#8221; link_font=&#8221;||||on||||&#8221; link_text_align=&#8221;left&#8221; link_text_color=&#8221;#FFFFFF&#8221; background_color=&#8221;#214C64&#8243; text_orientation=&#8221;center&#8221; custom_padding=&#8221;15px|10px|15px|10px|true|true&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;]<a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/routers\/sd-wan\/220448-identify-vedge-certificate-expired-on-ma.html\">Read the Cisco Article &#8211; Identify vEdge Certificate Expired on May 9th 2023<\/a>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]At the time of purchase it\u2019s hard to sign a check for a device that may not be used that often, but not only its used often, it actually saves money and increases productivity and here\u2019s how. [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>The Resilience System with out-of-band such as ZPE Systems Nodegrid Bold SR shown below creates an isolated control plane network (left side of graphic below) that can be accessed independent from the production network (right side of graphic below). IT admins and automation systems connect to this network through ZPE cloud to gain access to the system in production network. This is fundamental validated reference design that is now the foundational requirement for resilient networks. This solution will enable the engineers to securely update the certificates on Cisco Viptela. Automation built into the Resilience Systems, will enable all branches to be updated simultaneously.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||0px||false|false&#8221; custom_padding=&#8221;||0px||false|false&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h4>The Solution<\/h4>\n<h2>ZPE Systems Out-of-Band Infrastructure Recovery Kit<\/h2>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>ZPE is the leader in out-of-band serial console and service routers and directly addresses the resilience and uptime challenged this Cisco issue has caused. We are making our ZPE out-of-band recovery devices available as a subscription to help the community to address this immediate issue.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/Screenshot-2023-05-16-at-9.52.18-AM.png&#8221; alt=&#8221;Screenshot 2023-05-16 at 9.52.18 AM&#8221; title_text=&#8221;Screenshot 2023-05-16 at 9.52.18 AM&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Existing Viptela customers who are affected by the current issue and are struggling in recovering their Viptela environment across the globe, can utilize ZPE System\u2019s \u201cOut-of-Band Infrastructure Recovery Kit&#8221; to avoid truck rolls and bring sites up faster.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>The kit contains a <a href=\"https:\/\/zpesystems.com\/products\/branch-solutions\/mini-sr-zs\/\"><strong>Nodegrid Mini SR<\/strong><\/a>, with global LTE connectivity, a Cisco Console cable and all the connectivity and capabilities to recover your Viptela environment. Customers can order the kit directly from ZPE Systems and we ship it to your HQ or any other location in the world. The unit will automatically call to ZPE Cloud, using its LTE connection. Using ZPE Cloud you claim the Nodegrid Mini SR unit and can gain access to the SD-WAN hardware console and management interface without the requirement to setup a complex VPN connection or client. The setup is easy and with zero-attack surface in the remote location.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]Administrators can easily distribute the Viptela firmware to all locations using ZPE Cloud storage and use the build-in tools to recover the Viptela appliances, without the need to send a highly skilled and over-worked network admin on-site.  And we have experts on standby to help you with the scripts you need to enable the recovery. [\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||0px||false|false&#8221; custom_padding=&#8221;||0px||false|false&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>ZPE Systems Out-of-Band Infrastructure Recovery Kit &#8211; Overview<\/h3>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row use_custom_gutter=&#8221;on&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/HSR-KIT.jpg&#8221; alt=&#8221;HSR-KIT&#8221; title_text=&#8221;HSR-KIT&#8221; _builder_version=&#8221;4.23.4&#8243; _module_preset=&#8221;default&#8221; max_width=&#8221;50%&#8221; module_alignment=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;||||||||&#8221; text_text_color=&#8221;#FFFFFF&#8221; background_color=&#8221;#358AAF&#8221; custom_padding=&#8221;10px|15px|10px|15px|true|true&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>SKU: ZPE-MSR-24-4G-KIT<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<ul>\n<li>ZPE Systems Nodegrid Mini SR, with global LTE modem and global data sim covering, allowing the unit to communicate with ZPE Cloud out of the box<\/li>\n<li>Buit-in global LTE modem<\/li>\n<li>ZPE Cloud \u2013 provide global VPN and Clientless communication with MiniSR<\/li>\n<li>ZPE Cloud Storage holds the vEdge images<\/li>\n<li>USB Cisco console cable<\/li>\n<li>All required tools to recover the Viptela appliance, including TFTP, Console access, connectivity testing and more<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||0px||false|false&#8221; custom_padding=&#8221;||0px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Get your Out-of-Band Recovery Kit to fix those ticking time bombs<\/h3>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; use_custom_gutter=&#8221;on&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;||||||||&#8221; text_text_color=&#8221;#FFFFFF&#8221; background_color=&#8221;#214C64&#8243; custom_padding=&#8221;15px|15px|15px|15px|true|true&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Please get in touch with us if you need more details on the Out-of-Band Recovery Kit or want a trial unit. Send an email to info@zpesystems.com or use the form to get started.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.27.0&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<script src=\"\/\/www1.raritan.com\/js\/forms2\/js\/forms2.min.js\"><\/script> <\/p>\n<form id=\"mktoForm_8696\"><\/form>\n<p> <script>MktoForms2.loadForm(\"\/\/www1.raritan.com\", \"004-BTR-463\", 8696);<\/script>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Viptela SD-WAN devices are used at large enterprise branches all around the world. The success of SD-WAN replaced dedicated service provider managed MPLS with customer managed boxes that used commodity internet connectivity giving more options and power to leadership and engineering. It solved the single-point-of-failure issues with Internet connectivity and using overlay networking, created a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":35452,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[32,82],"tags":[],"class_list":["post-35405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-datacenter-management","category-out-of-band-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Defusing Cisco SD-WAN Time-bomb requires out-of-band access - ZPE Systems<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Defusing Cisco SD-WAN Time-bomb requires out-of-band access\" \/>\n<meta property=\"og:description\" content=\"Viptela SD-WAN devices are used at large enterprise branches all around the world. The success of SD-WAN replaced dedicated service provider managed MPLS with customer managed boxes that used commodity internet connectivity giving more options and power to leadership and engineering. It solved the single-point-of-failure issues with Internet connectivity and using overlay networking, created a [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-15T19:33:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-12T18:33:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png\" \/>\n\t<meta property=\"og:image:width\" content=\"675\" \/>\n\t<meta property=\"og:image:height\" content=\"468\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"ZPE Systems\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ZPE Systems\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/\",\"url\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/\",\"name\":\"Defusing Cisco SD-WAN Time-bomb requires out-of-band access - ZPE Systems\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png\",\"datePublished\":\"2023-05-15T19:33:33+00:00\",\"dateModified\":\"2024-08-12T18:33:27+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/8d210ea638908aafedfd8971473e7de6\"},\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png\",\"width\":675,\"height\":468},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Defusing Cisco SD-WAN Time-bomb requires out-of-band access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/8d210ea638908aafedfd8971473e7de6\",\"name\":\"ZPE Systems\",\"url\":\"https:\/\/zpesystems.com\/author\/alvin-chan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Defusing Cisco SD-WAN Time-bomb requires out-of-band access - ZPE Systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/","og_locale":"en_US","og_type":"article","og_title":"Defusing Cisco SD-WAN Time-bomb requires out-of-band access","og_description":"Viptela SD-WAN devices are used at large enterprise branches all around the world. The success of SD-WAN replaced dedicated service provider managed MPLS with customer managed boxes that used commodity internet connectivity giving more options and power to leadership and engineering. It solved the single-point-of-failure issues with Internet connectivity and using overlay networking, created a [&hellip;]","og_url":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/","og_site_name":"ZPE Systems","article_published_time":"2023-05-15T19:33:33+00:00","article_modified_time":"2024-08-12T18:33:27+00:00","og_image":[{"width":675,"height":468,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png","type":"image\/png"}],"author":"ZPE Systems","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ZPE Systems","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/","url":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/","name":"Defusing Cisco SD-WAN Time-bomb requires out-of-band access - ZPE Systems","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png","datePublished":"2023-05-15T19:33:33+00:00","dateModified":"2024-08-12T18:33:27+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/8d210ea638908aafedfd8971473e7de6"},"breadcrumb":{"@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png","width":675,"height":468},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/defusing-cisco-sd-wan-time-bomb-requires-out-of-band-access\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"Defusing Cisco SD-WAN Time-bomb requires out-of-band access"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/8d210ea638908aafedfd8971473e7de6","name":"ZPE Systems","url":"https:\/\/zpesystems.com\/author\/alvin-chan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-150x150.png",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-300x208.png",300,208,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-400x250.png",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-400x284.png",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-510x382.png",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-400x468.png",400,468,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit.png",675,468,false],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/RecoveryKit-480x333.png",389,270,true]},"rttpg_author":{"display_name":"ZPE Systems","author_link":"https:\/\/zpesystems.com\/author\/alvin-chan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/datacenter-management\/\" rel=\"category tag\">Data Center Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/out-of-band-management\/\" rel=\"category tag\">Out of Band Management<\/a>","rttpg_excerpt":"Viptela SD-WAN devices are used at large enterprise branches all around the world. The success of SD-WAN replaced dedicated service provider managed MPLS with customer managed boxes that used commodity internet connectivity giving more options and power to leadership and engineering. It solved the single-point-of-failure issues with Internet connectivity and using overlay networking, created a&hellip;","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/35405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=35405"}],"version-history":[{"count":10,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/35405\/revisions"}],"predecessor-version":[{"id":225794,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/35405\/revisions\/225794"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/35452"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=35405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=35405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=35405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}