Branch Gateway Full Mesh Topology
Learn how Branch Gateways operate in full-mesh topologies with standard branches and
data centers.
| Where Can I Use This? | What Do I Need? |
- Prisma SD-WAN (Managed by Strata Cloud Manager)
|
- Prisma SD-WAN
- Physical and virtual ION devices running software version 6.8.1
and higher for Branch Gateway full mesh support
|
You can deploy Prisma SD-WAN ION devices as Branch Gateways in a full-mesh topology with
standard branches and data centers, enabling flexible traffic routing across multiple
interconnected sites. In this architecture, Branch Gateways act as regional transit
points that can forward traffic between branches, reducing reliance on centralized data
centers and improving performance for branch-to-branch communication.
The network topology illustrated below represents an example reference architecture.
Prisma SD-WAN supports multiple full-mesh deployment designs based on your specific
enterprise requirements
When branches communicate through Branch Gateways, traffic uses the most direct available
path. For branch-to-branch traffic, the system prefers routing through interconnected
Branch Gateways rather than transiting the data center, optimizing latency and reducing
load on centralized infrastructure. If a direct connection between Branch Gateways is
unavailable, traffic automatically routes through the data center as a backup path. For
data center-to-branch traffic, the system selects the shortest available path, which may
be a direct connection or a path that transits one or more Branch Gateways depending on
the current network topology and link availability.
When a multi-hop path (such as Hop Count 2) fails, the controller takes up to 3
minutes to withdraw those prefixes from the WAN path. Active flows using that Branch
Gateway path experience temporary traffic disruption until the controller completes
the withdrawal.
The system prevents routing loops inherently during the path selection process. Whenever
path selection is triggered, it tracks the source location of each traffic flow and
excludes paths that would route traffic back toward its origin. By applying this logic
dynamically during routing decisions, the system adapts to link failures and topology
changes to maintain stable, loop-free routing across the full-mesh network.