Prisma SD-WAN supports layer 3 capabilities on loopback interfaces
for SSH and Syslog services on branch and data center ION devices.
The layer 3 capabilities on loopback interfaces are
supported from the device release 6.5.2 and above.
Prisma SD-WAN supports a maximum of 12 loopback
interfaces per ION device on all ION devices and virtual ION platforms.
L3 Loopback Interfaces for Management and Troubleshooting
Service Providers use L3 loopback interfaces on managed network devices
for troubleshooting tasks and management operations. As an example a loopback IP
interface can be used for SSH to the device or for Syslog services. An L3
loopback interface on the ION device allows management operations via the
overlay. As a result, you do not have to rely on LAN interfaces, which are part
of the infrastructure, or on WAN interfaces which involve using the underlay
leading to potential security considerations.
- The ION loopback interface is configured with the IP address
192.168.1.1/32.
- BGP sessions are running between ION eth1 and R1 and ION eth1 and R2.
Both the BGP sessions advertise the loopback interface IP address to the
routers R1 and R2.
- Users can configure the loopback interface as a source interface in
services such as Syslog.
- The Syslog packet generated in the ION device will use the loopback IP
address which will go out through eth1 to R1 and then to the Syslog
server.
- Using a loopback interface masks the physical interface IP address and
status.
Loopback Interface for establishing VPN Tunnels
You can establish Prisma SD-WAN tunnels using the loopback
interface when the MPLS WAN IP interfaces cannot be routed through the network.
In the example above, the Internet Service Provider (ISP) has provided an IP
address to an interface (the associate interface) and the Prisma SD-WAN VPN tunnel is formed over the loopback interface.
- You can configure an L3 Loopback interface with used for = public
or private for branch ION devices, and used for =
public and peer with network for data center ION
devices.
- To associate the interface, see the steps for configuring a Layer 3
loopback interface.
- The VPN is formed over the loopback interface IP address.
- The peer should be able to reach the loopback IP address via the
associated interface to form a VPN tunnel.
- You cannot use a loopback Interface to establish a Standard VPN
tunnel.
Configure a Layer 3 Loopback Interface