HPE Aruba Networking EdgeConnect SD-WAN Solution Guide
Focus
Focus
Prisma Access

HPE Aruba Networking EdgeConnect SD-WAN Solution Guide

Table of Contents

HPE Aruba Networking EdgeConnect SD-WAN Solution Guide

Learn to integrate the HPE Aruba Networking EdgeConnect SD-WAN (Manual Integration & Automated) with Prisma Access.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • HPE Aruba Networking EdgeConnect SD-WAN software version: 8.1.9.0
You onboard your SD-WAN edge devices using a remote network connection between the edge device at the branch site, HQ, or hub to Prisma Access. Use Prisma Access to create a remote network and configure IPSec and IKE Crypto profiles; then, set up an IPSec tunnel between the SD-WAN edge device and Prisma Access, using the same crypto profiles you used in Prisma Access.
The following table documents the IKE/IPSec crypto settings that are supported with Prisma Access and HPE Aruba Networking EdgeConnect SD-WAN (formerly Silver Peak). A check mark indicates that the profile or architecture type is supported; a dash (—) indicates that it's not supported. Default and Recommended settings are noted in the table.
Crypto ProfilesPrisma AccessHPE Aruba Networking EdgeConnect SD-WAN
Tunnel TypeIPSec Tunnel
√
√
GRE Tunnel——
RoutingStatic Routes
√
√
Dynamic Routing (BGP)
√
—
Dynamic Routing (OSPF)——
IKE VersionsIKE v1
√
√
IKE v2
√
—
IPSec Phase 1 DH-GroupGroup 1
√
√
Group 2
√
(Default)
√
Group 5
√
√
Group 14
√
√
(Recommended)
Group 19
√
√
Group 20
√
(Recommended)
—
IPSec Phase 1 Auth
If you use IKEv2 with certificate-based authentication, only SHA1 is supported in IKE crypto profiles (Phase 1).
MD5
√
—
SHA1
√
(Default)
√
(Recommended)
SHA256
√
√
SHA384
√
√
SHA512
√
(Recommended)
√
IPSec Phase 1 EncryptionDES
√
—
3DES
√
(Default)
—
AES-128-CBC
√
(Default)
√
AES-192-CBC
√
—
AES-256-CBC
√
(Recommended)
√
(Recommended)
IPSec Phase 1 Key Lifetime Default
√
(8 Hours)
√
(8 Hours Recommended)
IPSec Phase 1 Peer AuthenticationPre-Shared Key
√
Pre-Shared Key
Certificate
√
—
IKE Peer IdentificationFQDN
√
√
IP Address
√
√
User FQDN
√
√
IKE PeerAs Static Peer
√
√
As Dynamic Peer
√
—
OptionsNAT Traversal
√
√
Passive Mode
√
—
Ability to Negotiate TunnelPer Subnet Pair
√
—
Per Pair of Hosts
√
—
Per Gateway Pair
√
√
IPSec Phase 2 DH-GroupGroup 1
√
√
Group 2
√
(Default)
√
Group 5
√
√
Group 14
√
√
(Recommended)
Group 19
√
√
Group 20
√
(Recommended)
—
No PFS
√
√
IPSec Phase 2 AuthMD5
√
—
SHA1
√
(Default)
√
SHA256
√
√
(Recommended)
SHA384
√
√
SHA512
√
(Recommended)
√
None
√
—
IPSec Phase 2 EncryptionDES
√
—
3DES
√
(Default)
—
AES-128-CBC
√
(Default)
√
AES-192-CBC
√
—
AES-256-CBC
√
√
(Recommended)
AES-128-CCM
√
—
AES-128-GCM
√
—
AES-256-GCM
√
(Recommended)
—
NULL
√
√
IPSec ProtocolESP
√
√
AH
√
—
IPSec Phase 2 Key Lifetime Default
√
(1 Hour)
√
(Recommended 1 Hour
Lifebytes also supported
Tunnel Monitoring FallbackDead Peer Detection (DPD)
√
√
ICMP—
√
(HTTP GET also supported)
Bidirectional Forwarding Detection (BFD)——
SD-WAN Architecture TypeWith Regional Hub/Gateway/Data CenterN/A
√
No Regional Hub/Gateway/Data CenterNA
√