| Where Can I Use
This? | What Do I
Need? |
- Prisma SD-WAN (Managed by Strata Cloud Manager)
|
- Prisma SD-WAN
- ION device software version 6.5.1 and higher
|
Prisma SD-WAN supports secure SD-WAN fabric tunnels between
branch sites, eliminating the need for third-party solutions or complex MPLS
configurations. You can easily provision and manage these inter-branch connections
through the Prisma SD-WAN controller web interface or via APIs.
You can configure the secure SD-WAN fabric tunnels by choosing the source
and destination branch sites for creating VPNs. The secure fabric tunnels are
created by default between all the devices in a branch cluster. The secure fabric
tunnels are active by default on the active device and inactive on the standby
device.
Prisma SD-WAN uses addresses from the RFC 6598 Shared Address Space
(100.64.0.0/10) for the internal VPN tunnel interfaces of
Secure Fabric links. Each fabric VPN tunnel uses a /31 address from this range,
starting from the lowest. Do not use any address in this range for branch or
data center LAN networks that connect to the Prisma SD-WAN fabric. If a
connected or locally learned network overlaps with the internal VPN tunnel
address on the ION device, it could cause routing conflicts and disrupt fabric
connectivity. The portion of 100.64.0.0/10 that Prisma SD-WAN
consumes grows with the number of sites and WAN circuits in your
deployment.
To create Secure Fabric tunnels: