Use the following steps to configure the IPSec tunnel in Cisco Catalyst. The
examples in this section use command-line interface (CLI) commands.
This configuration completes the remote network connection between Prisma Access
and the Cisco Catalyst SD-WAN. The following figure shows what you define in the
Cisco Catalyst side:
On the LAN side of the Cisco Catalyst SD-WAN device, create a ge0/0
interface with an IP address of 10.50.50.1. This matches the IP address
you specified when you configured the IKE Gateway
in Prisma Access.
The Cisco Catalyst SD-WAN performs NAT on the source IP address for the
LAN (73.146.228.139).
On the remote network tunnel (WAN) side, create an interface named
ipsec2 with a type, slot, and port of ge0/4
whose IP address is 10.10.10.1/30.
This address must be within the subnet range you specified for the
Branch IP Subnet when you onboarded your
remote network in Prisma Access. In this example, the administrator
specified a Branch IP Subnet of 10.10.10.0/30 in
Prisma Access, and you use the other available IP address
(10.10.10.1/30) on the Cisco Catalyst side of the remote network
connection.
Specify a tunnel-destination IP address that
matches the Prisma Access Service IP Address.
This example uses 13.1.1.1.
Specify a loopback IP address that Prisma Access
can use for tunnel monitoring.
In this example, the administrator configured a
loopback100 interface with an IP address of
10.1.50.1/32. This value matches the Tunnel
Monitor
Destination IP address you specified in the
IPSec Tunnel configuration that you
configured in Prisma Access.