Link Type |
Select the physical link type from the predefined list
(ADSL/DSL, Cable
Modem, Ethernet,
Fiber,
LTE/3G/4G/5G,
MPLS, Microwave/Radio,
Satellite, WiFi,
Private
Link1, Private Link2,
Private Link3, Private
Link4, or Other).
With PAN-OS 11.1.3,
SD-WAN plugin 3.2.1 and later releases support the additional
point-to-point private link types, Private
Link1, Private Link2,
Private Link3, and Private
Link4.
The firewall can support any CPE device that terminates and hands off
as an Ethernet connection to the firewall; for example, WiFi access
points, LTE modems, laser-microwave CPEs all can terminate with an
Ethernet hand-off.
For existing PAN-OS deployments that have zones defined on interfaces that will be used to
support SD-WAN, Panorama may automatically configure the
interface’s zone name to one of the predefined SD-WAN zones
under the following conditions: 1. The SD-WAN interface is configured as a point-to-point private
link type (MPLS,
Satellite, Private
Link1, Private Link2,
Private Link3, Private
Link4, or
Microwave) in its Interface
Profile. 2. The VPN Data Tunnel Support checkbox is
disabled (unchecked) on the SD-WAN Interface Profile. This
instructs PAN-OS to forward traffic in clear text outside of the
SD-WAN VPN tunnel. Because Private Link1,
Private Link2, Private
Link3, and Private
Link4 link types don't support plain text
traffic from SD-WAN branch firewall to SD-WAN hub firewall,
you must leave the VPN Data Tunnel
Support option enabled when you configure
these private link types. On
the Hub firewall, the zone name is configured as “zone-to-branch”
when condition #1 is met. On the Branch firewall, the zone name
is configured as “zone-to-hub” when
both condition #1 and condition #2 are met. Panorama automates this
step to simplify configuration to ensure proper communication between
the hub and branch firewalls. If you have preexisting firewall policies
that referenced the old zone name, you must update the policies
to reflect the new predefined SD-WAN zone name.
|