---
title: "Cisco Catalyst SD-WAN"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1919221776/Cisco%20Catalyst%20SD-WAN"
format: markdown
---
Cisco Catalyst SD-WAN is a software-defined wide area networking solution that enables organizations to centrally manage, secure, and optimize connectivity across branch offices, data centers, and cloud environments. Using the Cisco Catalyst SD-WAN Manager, it provides deep visibility into network devices, links, policies, and routing behavior, allowing administrators to efficiently operate large, distributed networks.

Integrating **Cisco Catalyst SD-WAN** with **Universal Asset Insights** extends this visibility beyond network operations by continuously discovering and ingesting SD-WAN–related assets into a unified asset inventory. Through this integration, devices, interfaces, and associated IP information learned from Cisco Catalyst SD-WAN are correlated with data from other discovery sources, providing a single, authoritative view of assets across on-premises, branch, and cloud environments.

Universal Asset Insights connects to Cisco Catalyst SD-WAN Manager. 

> ℹ️ The Cisco Catalyst SD-WAN Manager must be accessible from the Infoblox Portal over the Internet using a publicly resolvable FQDN or a publicly routable IP address.

## API Permissions

Prior to configuring discovery, enable the following API permissions:

These are vManage feature-based RBAC roles (not AAD scopes). At the very minimum, assign the user to vManage's built-in `readonly` user group, which includes all of the following read permissions.

| Permission | Type | Admin Consent | Purpose |
| --- | --- | --- | --- |
| Routing – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read device routing and interface data |
| Device Monitoring – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read device system status |
| System – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read device inventory |
| Policy – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read ARP and interface policy data |
| Interface – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read wireless client data |
| Template Configuration – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read tenant and VPN resource pool data |
| Manage Users – Read | vManage Feature Role | Yes – Admin assigns user to `readonly` group | Read user information |

## Configuring Discovery for Cisco Catalyst SD-WAN

Complete the following steps to configure discovery for Cisco Catalyst SD-WAN:

1. **Provider Type:** Select **Cisco Catalyst SD-WAN** to specify Cisco Catalyst SD-WAN as the discovery source.
2. **Name:** Enter a unique and descriptive name to identify the discovery configuration, for example, `Cisco-SD-WAN-Production`.
3. **Description:** (Optional) Provide additional information describing the purpose or scope of this discovery source.
4. **Sync Interval:** Select **Auto** to allow the system to manage the synchronization frequency automatically.
5. **State:** Ensure the state is set to **Enabled** so that the discovery job runs according to the configured interval.
6. **Account Preference:** Select **Single** to use one credential set for all discovery operations. Alternatively, select **Auto-Discover multiple**.
7. **Type of access:** Select **Static Credential** to authenticate using stored credentials.
8. **Credentials:** To use an existing credential, select **Existing** to use a previously created credential.
9. Alternatively, choose **New** to create a new credential for this discovery source. Configure the following settings:
  1. **Credential Name:** Enter a unique and descriptive name to identify the credential.
  2. **Description:** (Optional) Provide additional information describing the purpose or usage of the credential.
  3. **Username:** Enter the vManage user name created within the Cisco-managed SD-WAN cloud environment. This account must have API access and sufficient privileges to retrieve device inventory, topology, and network information.
  4. **Password:** Specify the password associated with the **Username**.
  5. **Add Tags:** (Optional) Add tags to the credential to support classification, filtering, and governance.
  6. **Save Credential:** Click **Save** to save the credential and confirm that it is available for selection in the **Credentials** list.
10. **Endpoint:** Enter the URL of the controller endpoint for Cisco Catalyst SD-WAN, which Infoblox uses to securely connect to the SD-WAN management plane and discover network assets and configuration data. In all deployment scenarios, the endpoint must be reachable over HTTPS and correctly resolve in DNS to enable authentication and continuous discovery. Use the publicly accessible HTTPS URL provided by Cisco. This endpoint is internet-facing and typically requires no additional network configuration beyond standard access permissions.
11. **Destination – Disable IPAM Discovery:** Enable this option if you want to prevent IP address and subnet information from being discovered and synchronized into IPAM.
12. **User Defined tags:** Review whether any tags are already associated with the discovery configuration.
13. **Manage Tags:** Add, edit, or remove tags to support classification, filtering, and governance.
14. Click **Save** to save the discovery configuration.

Go to *[Managed Assets](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/1161494602)* to view the assets discovered from Cisco Catalyst SD-WAN.