Branch Gateway Full Mesh Topology
Focus
Focus
Prisma SD-WAN

Branch Gateway Full Mesh Topology

Table of Contents

Branch Gateway Full Mesh Topology

Learn how Branch Gateways operate in full-mesh topologies with standard branches and data centers.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma SD-WAN
  • Physical and virtual ION devices running software version 6.8.1 and higher for Branch Gateway full mesh support
You can deploy Prisma SD-WAN ION devices as Branch Gateways in a full-mesh topology with standard branches and data centers, enabling flexible traffic routing across multiple interconnected sites. In this architecture, Branch Gateways act as regional transit points that can forward traffic between branches, reducing reliance on centralized data centers and improving performance for branch-to-branch communication.
The network topology illustrated below represents an example reference architecture. Prisma SD-WAN supports multiple full-mesh deployment designs based on your specific enterprise requirements
When branches communicate through Branch Gateways, traffic uses the most direct available path. For branch-to-branch traffic, the system prefers routing through interconnected Branch Gateways rather than transiting the data center, optimizing latency and reducing load on centralized infrastructure. If a direct connection between Branch Gateways is unavailable, traffic routes via a different path based on path policy, with the data center serving as a backup. For data center-to-branch traffic, the system selects the most direct available path based on path policy, which may be a direct connection or a path that transits one or more Branch Gateways.
When a multi-hop path (such as Hop Count 2) fails, the controller takes up to 3 minutes to withdraw those prefixes from the WAN path. Any flows using that Branch Gateway path—including active flows and new flows established during convergence—experience temporary traffic disruption until the controller completes the withdrawal.
The system prevents routing loops inherently during the path selection process. Whenever path selection is triggered, it tracks the source location of each traffic flow and excludes paths that would route traffic back toward its origin. By applying this logic dynamically during routing decisions, the system adapts to link failures and topology changes to maintain stable, loop-free routing across the full-mesh network.