Primsa SD-WAN now supports Configure Intra Cluster Tunnel, set the Tunnel peer
address as part of the Interface configuration to send this traffic to the peer
DC-ION.
Where Can I Use
This?
What Do I Need?
Prisma SD-WAN
Prisma SD-WAN license
Route aggregation allows you to combine groups of routes with common addresses into a
single entry in the routing table. This decreases the size of the routing table as
well as the number of route advertisements sent by the routing device. Route
aggregation works when it has one or more contributing route.
Similarly, different branch prefixes can be aggregated to the same range when the
same aggregation ranges are configured on DC IONs. The DC core router might treat
this summary route advertisement as ECMP and mistakenly send some traffic to ION,
which it cannot forward. In this scenario, the traffic gets blackholed, meaning it
is lost in the network and does not reach its intended destination. To avoid this,
the admin will set the Tunnel peer address as part of the Interface configuration to
send this traffic to the peer DC-ION so it can be forwarded appropriately.
Branch traffic using Standard VPN tunnels to reach the core has the potential for
asymmetry. The DC-ION receives a request from the Standard VPN tunnel and forwards
it to the core router. Upon receiving the response, DC-ION follows the same flow and
sends it over the Standard VPN instead of fabric towards the branch, provided the
route map is attached to the BGP peer over Standard VPN to prefer the Standard VPN
path.
Select WorkflowsData Centers, and select a site from the list of Data Center sites.
Click ConfigurationsAdvancedConfigure Intra Cluster Tunnel to send this traffic to the peer DC-ION, which has an Active VPN
to the branch and can forward it appropriately.
On the Configure Intra Cluster Tunnel tab, select
Devices to Cluster and Interface. Then, if you want
select Shutdown to shut down the device's chosen cluster
and Close.