To start installing and configuring SD-WAN controllers, the first step is to prepare a SD-WAN certificate authority server, since certificate is the main authentication method between controllers and also SD-WAN routers. all components of the SD-WAN architecture receive their own certificate from the certificate authority. this is what we will do in this section.
Introduction to Cisco SD-WAN Architecture
I have already prepared a Windows Server 2012 with installed Active Directory, in which I will install a certification authority and prepare a template for the SD-WAN architecture.
![](https://rayka-co.com/wp-content/uploads/2021/09/image-1024x691.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-2-1024x729.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-3-1024x726.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-4-1024x727.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-5-1024x727.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-6-1024x726.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-8-1024x724.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-10-1024x729.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-11-1024x726.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-12-1024x725.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-13-1024x725.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-14-1024x725.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-15-1024x723.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-16-1024x727.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-17-1024x726.png)
After installation, we receive a message to configure certificate service in Active Directory.
![](https://rayka-co.com/wp-content/uploads/2021/09/image-18-1024x686.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-19-1024x750.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-20-1024x750.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-21-1024x751.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-22-1024x745.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-23-1024x751.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-24-1024x752.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-25-1024x749.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-26-1024x746.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-27-1024x752.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-28-1024x751.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-29-1024x752.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-30-1024x690.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-31-1024x756.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-32-1024x752.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-33-1024x750.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-34-1024x755.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-35-1024x683.png)
This step requires an account member of IIS_USERS group. So I will add administrator user as a member of IIS_USERS group before continuing.
![](https://rayka-co.com/wp-content/uploads/2021/09/image-36-1024x715.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-37-1024x756.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-38-1024x756.png)
now that administrator is a member of IIS_USERS group, we can choose administrator account in the installation process
![](https://rayka-co.com/wp-content/uploads/2021/09/image-39-1024x748.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-40-1024x747.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-41-1024x751.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-42-1024x747.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-44-1024x749.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-45-1024x754.png)
Now I want to prepare a certificate template for SD-WAN infrastructure. The application of certificate should include both client authentication and server authentication.
![](https://rayka-co.com/wp-content/uploads/2021/09/image-46-1024x541.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-57-737x1024.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-47-1024x538.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-49-1024x543.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-50-1024x541.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-51-748x1024.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-52-751x1024.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-53-754x1024.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-54-738x1024.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-55-1024x538.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-56-1024x653.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-58-1024x543.png)
now we check to see if new template is into the list.
![](https://rayka-co.com/wp-content/uploads/2021/09/image-59-1024x513.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-61-1024x519.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-62-1024x515.png)
![](https://rayka-co.com/wp-content/uploads/2021/09/image-63-1024x513.png)