Link Type |
Select the physical link type from the predefined list
(ADSL/DSL, Cable
Modem, Ethernet,
Fiber,
LTE/3G/4G/5G,
MPLS, Microwave/Radio,
Satellite, WiFi,
Private
Link1, Private Link2,
Private Link3, Private
Link4, or
Other).
With PAN-OS 11.1.3, SD-WAN
plugin 3.2.1 and later releases support the additional
point-to-point private link types, Private
Link1, Private Link2,
Private Link3, and Private
Link4.
The firewall can support any CPE device that
terminates and hands off as an Ethernet connection to the firewall;
for example, WiFi access points, LTE modems, laser-microwave CPEs
all can terminate with an Ethernet hand-off.
For existing PAN-OS deployments that have zones defined on
interfaces that will be used to support SD-WAN, Panorama may
automatically configure the interface’s zone name to one of the
predefined SD-WAN zones under the following conditions: 1. The SD-WAN interface is configured as a point-to-point private
link type (MPLS,
Satellite,
Private
Link1, Private Link2,
Private Link3, Private
Link4,
or Microwave) in its
Interface Profile. 2. The VPN Data Tunnel Support checkbox is
disabled (unchecked) on the SD-WAN Interface Profile. This
instructs PAN-OS to forward traffic in clear text outside of the
SD-WAN VPN tunnel.
Because
Private Link1, Private
Link2, Private Link3,
and Private Link4 link types don't
support plain text traffic from SD-WAN branch firewall to
SD-WAN hub firewall, you must leave the VPN Data
Tunnel Support option enabled when you
configure these private link
types. On the Hub firewall, the zone name is configured as
“zone-to-branch” when condition
#1 is met. On the Branch firewall, the zone name is configured
as “zone-to-hub” when both
condition #1 and condition #2 are met. Panorama automates this
step to simplify configuration to ensure proper communication
between the hub and branch firewalls. If you have preexisting
firewall policies that referenced the old zone name, you must
update the policies to reflect the new predefined SD-WAN zone
name.
|