| Where Can I Use
This? | What Do I
Need? |
- Prisma SD-WAN (Managed by Strata Cloud Manager)
|
- Prisma SD-WAN
- ION device software version 6.5.1 and higher
|
Prisma SD-WAN supports secure SD-WAN fabric tunnels between
data center sites, eliminating the need for third-party solutions or complex MPLS
configurations. With this feature, you can efficiently connect multiple data centers
across different cloud providers such as AWS, Azure, Equinix, and GCP, as well as
physical locations. You can easily provision and manage these inter-DC connections
through the Prisma SD-WAN controller web interface or via APIs,
similar to how you set up branch-to-branch tunnels.
Both the source and destination DC ION devices should have software version
6.5.1 or later to configure such tunnels.
You can configure the secure SD-WAN fabric tunnels by choosing the source
and optional destination clusters between the DC sites for creating VPNs. The secure
fabric tunnels are created by default between all the devices in a DC cluster.
All the secure fabric tunnels will be active by default based on the core
peering status. If the core peer is down, the controller marks the VPN as inactive.
We recommend that you configure either Standard VPN tunnels or secure fabric tunnels
between two data center sites and not both at the same time.
In case you have a hybrid topology, where you have both native and standard
VPNs, configure a prefix list for the first data center, which explicitly denies the
prefixes coming from the second data center on the Standard VPN path. Otherwise, the
traffic loops back to the first DC device.
After setting up secure fabric tunnels, you should refrain from distributing
Inter-DC-BGP learned prefixes over Inter-DC tunnels. Hence, after upgrading your
device to software version 6.5.1,
Prisma SD-WAN sets all the existing
BGP peers to
Local. This is to have better control over the
learned prefixes. If you want to distribute the learned prefixes, you will need to
change the setting to
Global.
To create Secure Fabric tunnels: