Citrix SD-WAN Solution Guide
Focus
Focus
Prisma Access

Citrix SD-WAN Solution Guide

Table of Contents

Citrix SD-WAN Solution Guide

The following sections describe how you use the Citrix SD-WAN with Prisma Access to provide next-generation security on internet-bound traffic.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
To use this Solution Guide, you need a knowledge of SD-WAN routing principles.
You onboard your SD-WAN edge devices using a remote network connection between the edge device at the branch site, HQ, or hub to Prisma Access. To do this you Onboard a Remote Network, ensuring that you use supported IKE and IPSec cryptographic settings detailed here.
The following table documents the IKE/IPSec crypto settings that are supported with Prisma Access and the Citrix SD-WAN.
A check mark indicates that the profile or architecture type is supported; a dash (—) indicates that it's not supported. Default and Recommended settings are noted in the table.
Crypto ProfilesPrisma AccessCitrix SD-WAN
Tunnel TypeIPSec Tunnel
√
√
GRE Tunnel—
√
RoutingStatic Routes
√
√
Dynamic Routing (BGP)
√
√
Dynamic Routing (OSPF)—
√
IKE VersionsIKE v1
√
√
IKE v2
√
√
IPSec Phase 1 DH-GroupGroup 1
√
√
Group 2
√
(Default)
√
Group 5
√
√
Group 14
√
√
Group 19
√
√
Group 20
√
(Recommended)
√
IPSec Phase 1 Auth
If you use IKEv2 with certificate-based authentication, onlySHA1 is supported IKE Crypto profiles (Phase 1).
MD5
√
√
SHA1
√
(Default)
√
SHA256
√
√
SHA384
√
—
SHA512
√
(Recommended)
—
IPSec Phase 1 EncryptionDES
√
—
3DES
√
(Default)
—
AES-128-CBC
√
(Default)
√
AES-192-CBC
√
√
AES-256-CBC
√
(Recommended)
√
IPSec Phase 1 Key Lifetime Default
√
(8 Hours)
√
(1 day)
IPSec Phase 1 Peer AuthenticationPre-Shared Key
√
√
Certificate
√
√
IKE Peer IdentificationFQDN
√
—
IP Address
√
√
User FQDN
√
—
IKE PeerAs Static Peer
√
√
As Dynamic Peer
√
√
OptionsNAT Traversal
√
√
Passive Mode
√
√
Ability to Negotiate TunnelPer Subnet Pair
√
√
Per Pair of Hosts
√
√
Per Gateway Pair
√
√
IPSec Phase 2 DH-GroupGroup 1
√
√
Group 2
√
(Default)
√
Group 5
√
√
Group 14
√
√
Group 19
√
√
Group 20
√
(Recommended)
√
No PFS
√
√
(Default)
IPSec Phase 2 AuthMD5
√
√
SHA1
√
(Default)
√
SHA256
√
√
SHA384
√
—
SHA512
√
(Recommended)
—
None
√
√
IPSec Phase 2 EncryptionDES
√
—
3DES
√
(Default)
—
AES-128-CBC
√
(Default)
√
AES-192-CBC
√
√
AES-256-CBC
√
√
AES-128-CCM
√
—
AES-128-GCM
√
√
AES-256-GCM
√
(Recommended)
√
NULL
√
√
IPSec ProtocolESP
√
√
AH
√
√
IPSec Phase 2 Key Lifetime Default
√
(1 Hour)
√
(1 Day Max)
Tunnel Monitoring FallbackDead Peer Detection (DPD)
√
√
ICMP——
Bidirectional Forwarding Detection (BFD)——
SD-WAN Architecture TypeWith Regional Hub/Gateway/Data CenterN/A
√
No Regional Hub/Gateway/Data CenterNA
√