Configure a Logical Router (Strata Cloud Manager)
Focus
Focus
Next-Generation Firewall

Configure a Logical Router (Strata Cloud Manager)

Table of Contents


Configure a Logical Router (Strata Cloud Manager)

Procedure for configuring a logical router in Strata Cloud Manager.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationNGFW and Prisma Access and from the Configuration Scope, select the device where you want to create the Logical Router.
    You can select a folder or firewall from your Folders or select Snippets to configure the logical router in a snippet.
    The number of logical routers supported varies based on the firewall model. If you create multiple logical routers for a folder or snippet, verify that the firewalls associated with the folder or snippet support the number of logical routers you configure.
  3. Select Network & DeviceRoutingLogical Routers tab.
    On new Strata™ Cloud Manager tenants, the Routing page displays both Logical Routers and Virtual Routers tabs; existing Strata™ Cloud Manager tenants see only the Logical Routers tab.
  4. Add Logical Routers.
  5. Enter a descriptive Name.
    A maximum of 31 characters are supported. The name must start with an alphanumeric character, underscore (_), or hyphen (-) and can contain a combination of alphanumeric characters, underscore (_), or hyphen (-). A dot (.) or space isn’t supported.
  6. (Optional) Configure Equal Cost Multiple Path (ECMP) processing.
    Enabling this setting enables the firewall to use up to four equal-cost routes to the same destination.
    1. Enable ECMP.
    2. Set the ECMP Max Path to specify the maximum number of equal-cost paths that can be copied from the RIB to the FIB.
      Default is 2. 2, 3, or 4 are supported.
    3. Enable Symmetric Return of packets from server to client.
      Select Symmetric Return to cause return packets to egress out the same interface on which the associated ingress packets arrived. That is, the firewall will use the ingress interface on which to send return packets, rather than use the ECMP interface. The Symmetric Return setting overrides load balancing. This behavior occurs only for traffic flows from the server to the client.
    4. Enable Strict Source Path o ensure that IKE and IPSec traffic originating at the firewall egresses the physical interface to which the source IP address of the IPSec tunnel belongs.
      When you enable ECMP, IKE and IPSec traffic originating at the firewall by default egresses an interface that an ECMP load-balancing method determines. Alternatively, you can ensure that IKE and IPSec traffic originating at the firewall always egresses the physical interface to which the source IP address of the IPSec tunnel belongs, by enabling Strict Source Path. You would enable this function when the firewall has more than one ISP providing equal-cost paths to the same destination. ISPs typically perform a reverse Path Forwarding (RPF) check (or a different check to prevent IP address spoofing) to confirm that traffic is egressing the same interface on which it arrived. Because ECMP would choose an egress interface based on the configured ECMP method (instead of choosing the source interface as the egress interface), that wouldn’t be what the ISP expects and the ISP could block legitimate return traffic. In this case, enable Strict Source Path so that the firewall uses the egress interface that is the interface to which the source IP address of the IPSec tunnel belongs, the RPF check succeeds, and the ISP allows the return traffic.
    5. Specify the load-balance Action for the logical router.
      • IP Modulo—Uses a hash of the source and destination IP addresses in the packet header to determine which ECMP route to use.
      • IP Hash—Use a hash of the source and destination IP addresses to determine which ECMP route to use.
        If you select this option, can select to Use Source Address Only and Use Source/Destination port for hash.
      • Weighted Round Robin—Uses round-robin and a relative weight to select from among ECMP paths.
      • Balanced Round Robin (default)—Uses round-robin among the ECMP paths and rebalances paths when the number of paths changes.
  7. Add an Interface to the logical router.
    • Add an interface to the logical router by selecting from the list of interfaces. An interface can belong to only one logical router. Repeat to add more Layer 3, loopback, and tunnel interfaces as needed.
  8. (Optional) Select Administrative Distances to change the global administrative distance from the default setting for various types of routes.
    When the logical router has two or more different routes to the same destination, it uses administrative distance to choose the best path, preferring a lower distance.
    1. Select Advanced SettingsAdministrative Distances.
    2. Set the administrative distances as required for your network.
      • Static—Range is 1 to 255; default is 10.
      • Static IPv6—Range is 1 to 255; default is 10.
      • OSPF Intra Area—Range is 1 to 255; default is 110.
      • OSPF Inter Area—Range is 1 to 255; default is 110.
      • OSPF External—Range is 1 to 255; default is 110.
      • OSPFv3 Intra Area—Range is 1 to 255; default is 110.
      • OSPFv3 Inter Area—Range is 1 to 255; default is 110.
      • OSPFv3 External—Range is 1 to 255; default is 110.
      • BGP AS Internal—Range is 1 to 255; default is 200.
      • BGP AS External—Range is 1 to 255; default is 20.
      • BGP Local Route—Range is 1 to 255; default is 20.
      • RIP—Range is 1 to 255; default is 120.
  9. Control the static routes that are placed in the global routing information base (RIB).
    You might configure static routes and redistribute them, but not want them in the protocol’s local route table or global RIB. You might want to add only specific static routes to the global RIB.
    1. Select Advanced SettingsRIB Filter to allow routes into or prevent routes from being added to the global RIB.
    2. To filter IPv4 static routes and connected routes, for Static Route-Map, select a Redistribution Route Map or create a new one.
    3. To filter IPv6 static routes and connected routes, for Static Route-Map, select a Redistribution Route Map or create a new one.
  10. Configure the following settings:
    • Static Route
    • BGP
    • Multicast IPv4
    • OSPF
    • OSPFv3
  11. Save.
  12. Push Config to push your configuration changes.

Clone a Logical Router

You can clone an existing Logical Router into a folder or snippet to use as a starting point for a new configuration, avoiding the need to build it from scratch.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationNGFW and Prisma Access and from the Configuration Scope, select the device.
  3. Select Network & DeviceRoutingLogical Routers tab.
  4. Select the router you want to Clone.
  5. For Destination Rule Type, choose Folders or Snippets.
  6. From Destination, choose the target folder or snippet.
  7. Enable Error out on first detected error in validation to stop the clone if validation fails.
  8. Clone the router.

Troubleshoot a Logical Router

You can view or search the routing table on a device directly from the Strata Cloud Manager.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationNGFW and Prisma Access and from the Configuration Scope, select the device.
  3. Select Network & DeviceRoutingLogical Routers tab.
  4. Select the router you want to Troubleshoot.
  5. Select the Troubleshooting Type: Routing.
  6. For Target Devices, choose the device to run the troubleshooting action on.
  7. For Action, choose one of the following: Show Routing Table and Search the Routing Table.
  8. Execute.