Select the physical link type from the predefined
list (ADSL/DSL, Cable Modem, Ethernet, Fiber, LTE/3G/4G/5G, MPLS, Microwave/Radio, Satellite, WiFi,
or Other). The firewall can support any CPE
device that terminates and hands off as an Ethernet connection to
the firewall; for example, WiFi access points, LTE modems, laser-microwave
CPEs all can terminate with an Ethernet hand-off.
For existing PAN-OS deployments that have zones defined on interfaces that will be used to
support SD-WAN, Panorama may automatically configure the
interface’s zone name to one of the predefined SD-WAN zones
under the following conditions: 1. The SD-WAN interface is
configured as a point-to-point private link type (MPLS, Satellite,
or Microwave) in its Interface Profile. 2.
The VPN Data Tunnel Support checkbox is disabled
(unchecked) on the SD-WAN Interface Profile. This instructs PAN-OS
to forward traffic in clear text outside of the SD-WAN VPN tunnel. On
the Hub firewall, the zone name is configured as “zone-to-branch”
when condition #1 is met. On the Branch firewall, the zone name
is configured as “zone-to-hub” when
both condition #1 and condition #2 are met. Panorama automates this
step to simplify configuration to ensure proper communication between
the hub and branch firewalls. If you have preexisting firewall policies that
referenced the old zone name, you must update the policies to reflect
the new predefined SD-WAN zone name.
|