Branch Gateway Full Mesh Topology
Focus
Focus
Prisma SD-WAN

Branch Gateway Full Mesh Topology

Table of Contents

Branch Gateway Full Mesh Topology

Learn how Branch Gateways operate in full-mesh topologies with standard branches and data centers.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma SD-WAN
  • Physical and virtual ION devices running software version 6.8.1 and higher for Branch Gateway full mesh support
You can deploy Prisma SD-WAN ION devices as Branch Gateways in a full-mesh topology with standard branches and data centers, enabling flexible traffic routing across multiple interconnected sites. In this architecture, Branch Gateways act as regional transit points that can forward traffic between branches, reducing reliance on centralized data centers and improving performance for branch-to-branch communication.
The network topology illustrated below represents an example reference architecture. Prisma SD-WAN supports multiple full-mesh deployment designs based on your specific enterprise requirements
When branches communicate through Branch Gateways, traffic uses the most direct available path. For branch-to-branch traffic, the system prefers routing through interconnected Branch Gateways rather than transiting the data center, optimizing latency and reducing load on centralized infrastructure. If a direct connection between Branch Gateways is unavailable, traffic automatically routes through the data center as a backup path. For data center-to-branch traffic, the system selects the shortest available path, which may be a direct connection or a path that transits one or more Branch Gateways depending on the current network topology and link availability.
When a multi-hop path (such as Hop Count 2) fails, the controller takes up to 3 minutes to withdraw those prefixes from the WAN path. Active flows using that Branch Gateway path experience temporary traffic disruption until the controller completes the withdrawal.
The system prevents routing loops inherently during the path selection process. Whenever path selection is triggered, it tracks the source location of each traffic flow and excludes paths that would route traffic back toward its origin. By applying this logic dynamically during routing decisions, the system adapts to link failures and topology changes to maintain stable, loop-free routing across the full-mesh network.