Integrate Prisma Access with Riverbed SteelConnect SD-WAN.
| Where Can I Use
This? | What Do I Need? |
|
|
- SteelConnect software version: 2.11
|
Use this workflow to configure three sites to use a ClassicVPN tunnel to establish
VPN connectivity with Prisma Access. Match the configuration in SCM with the
configuration in Prisma Access. Each management interface has its own default
settings, so we recommend that you confirm each setting between SCM and
Panorama.
This workflow assumes that you have already
configured the remote network tunnel
for the tunnels you want to create. You need the IP address of the Prisma Access
side of the tunnel to complete this configuration. To find this address in
Panorama, select and find the
Service IP Address in the
Remote Networks area.
The following figure shows a total of six RouteVPN tunnels. They are identified by
solid orange lines. SteelConnect automatically forms these tunnels over the internet
WAN between SteelConnect appliances. Three of these tunnels use the internet between
sites, and the other three use the MPLS cloud between sites. These tunnels form the
overlay network. This term is an abstraction of the internet and WAN in
which the gateways communicate with each other. The communication for the overlay
network takes place on an underlay network. The underlay network is the
series of network devices owned by a provider or customer making up a network
infrastructure.
The organizational networking defaults you set in SCM determine how the SD-WAN
processes traffic. For traffic going to the internet breakout, the traffic uses the
internet uplink. For traffic between sites, the SD-WAN prefers the RouteVPN over the
internet uplink over the RouteVPN over the MPLS WAN. Based on organizational
defaults, SCM automates the creation of a full-mesh RouteVPN over the internet
uplink and establishes encrypted tunnels over the MPLS network.
The following figure shows the internet breakout preferences as defined in SCM.
The following diagram illustrates the logical traffic flow. The traffic between
ThousandOaks and New York, HQ and New York, and HQ and ThousandOaks takes the
RouteVPN over the MPLS overlay by default, while traffic from each branch to the
internet takes the internet uplink by default. The workflow in this section
configures ClassicVPN tunnels and defines traffic rules in SCM so that traffic from
the SD-WAN to the internet takes the ClassicVPN tunnels to Prisma Access.
You can override organizational defaults by Traffic Path rules. The following figure
shows an SCM configuration that directs traffic between the New York site
172.16.3.0/24 subnet to the HQ 172.16.1.0/24 subnet or the ThousandOaks
172.16.2.0/24 subnet to use the RouteVPN tunnel instead of the ClassicVPN tunnels
used for internet traffic. The settings in SCM specify these tunnels to use the MPLS
WAN.
Internet traffic uses the ClassicVPN tunnel at each site. Traffic from the New York
LAN to the internet uses the ClassicVPN tunnel in New York. Traffic from
ThousandOaks to the internet uses the ClassicVPN tunnel in ThousandOaks, and traffic
from HQ to the internet uses the ClassicVPN tunnel in HQ.
This workflow creates and configures ClassicVPN tunnels between the SteelConnect
SD-WAN and Prisma Access.