SD-WAN
PAN-OS & Panorama
Table of Contents
Expand All
|
Collapse All
SD-WAN Docs
-
- SD-WAN Deployment Workflow
-
- Add SD-WAN Branch or Hub Firewall
- Configure Certificate-based Authentication for Strong Security
- Quickly Add Multiple SD-WAN Devices with Bulk Import
- Configure SD-WAN Devices in HA Mode
- Onboard PAN-OS Firewalls to Prisma Access for Cloud-based Security
- Plan Your Topology for SD-WAN with Auto VPN
- Create a Full Mesh VPN Cluster with DDNS Service
- Create a Static Route for SD-WAN
- Configure Advanced Routing for SD-WAN
PAN-OS & Panorama
In PAN-OS, configure a Software-as-a-Service (SaaS) quality profile to
specify a SaaS application for a hub firewall with a Direct Internet Access (DIA)
link.
- Select ObjectsSD-WAN Link ManagementSaaS Quality Profile and specify the Device Group containing your SD-WAN configuration.
- Add a new SaaS quality profile.
- Enter a descriptive Name for the SaaS Quality profile.
- (Optional) Enable (check) Shared to make the SaaS Quality profile shared across all device groups.
- (Optional) Enable (check) Disable override to disable overriding the SaaS Quality profile configuration on the local firewall.Disable override can only be enabled if Shared is disabled in the previous step.
- Configure the SaaS Monitoring Mode.
- Automatically monitor the SaaS application path health.Enabled by default, Adaptive monitoring allows the branch firewall to passively monitor the SaaS application session for send and receive activity to determine if the path quality thresholds have been exceeded. The SaaS application path health quality is automatically determined without any additional health checks on the SD-WAN interface.Adaptive SaaS monitoring is supported only for TCP SaaS applications.
- Configure the Static IP address for the SaaS application.Create a SaaS Quality profile per critical SaaS application that you need monitored. If a SaaS application has multiple IP addresses, configure a SaaS Quality profile with the multiple static IP addresses for that SaaS application.SaaS monitoring is resource-intensive and may impact firewall performance if monitoring a large number of SaaS applications. It is a best practice to only monitor those business-critical SaaS applications that need good usability.
- Select IP Address/ObjectStatic IP Address and Add an IP address.
- Enter the IP address of the SaaS application or select a configured address object.
- Enter the Probe Interval by which the branch firewall probes the SaaS application path for health information.
- Click OK to save your configuration changes.
- Configure the fully qualified domain name (FQDN) for the SaaS application.
- Configure a FQDN address object for the SaaS application.
- Select IP Address/ObjectFQDN and Add the FQDN.
- Select the FQDN address object for the SaaS application.
- Enter the Probe Interval by which the branch firewall probes the SaaS application path for health information.
- Click OK to save your configuration changes.
- Configure the URL for the SaaS application.URL monitoring is only supported for traffic over ports 80, 443, 8080, 8081, and 143.
- Select HTTP/HTTPS.
- Enter the Monitored URL of the SaaS application.
- Enter the Probe Interval by which the branch firewall probes the SaaS application path for health information.The minimum probe interval supported for a SaaS application HTTP/HTTPS is 3 seconds.
- Click OK to save your configuration changes.
- Select Commit and Commit and Push your configuration changes.