Configure Secure SD-WAN Fabric Tunnels between Branch Sites
Focus
Focus
Prisma SD-WAN

Configure Secure SD-WAN Fabric Tunnels between Branch Sites

Table of Contents

Configure Secure SD-WAN Fabric Tunnels between Branch Sites

Learn how to configure secure SD-WAN Fabric tunnels between sites in Prisma SD-WAN.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma SD-WAN
  • ION device software version 6.5.1 and higher
Prisma SD-WAN supports secure SD-WAN fabric tunnels between branch sites, eliminating the need for third-party solutions or complex MPLS configurations. You can easily provision and manage these inter-branch connections through the Prisma SD-WAN controller web interface or via APIs.
You can configure the secure SD-WAN fabric tunnels by choosing the source and destination branch sites for creating VPNs. The secure fabric tunnels are created by default between all the devices in a branch cluster. The secure fabric tunnels are active by default on the active device and inactive on the standby device.
Prisma SD-WAN uses addresses from the RFC 6598 Shared Address Space (100.64.0.0/10) for the internal VPN tunnel interfaces of Secure Fabric links. Each fabric VPN tunnel uses a /31 address from this range, starting from the lowest. Do not use any address in this range for branch or data center LAN networks that connect to the Prisma SD-WAN fabric. If a connected or locally learned network overlaps with the internal VPN tunnel address on the ION device, it could cause routing conflicts and disrupt fabric connectivity. The portion of 100.64.0.0/10 that Prisma SD-WAN consumes grows with the number of sites and WAN circuits in your deployment.
To create Secure Fabric tunnels:
  1. Select ConfigurationPrisma SD-WANBranch Sites Overlay Connections.
  2. Click Add Link.
    1. (Optional) Enter a Name, Description, and Tags for the secure fabric tunnel.
    2. Select a Circuit from the source branch site.
    3. Ensure that you select Admin Up.
    4. For Destination, select a Branch site and Circuit.
      You can select multiple destinations, Prisma SD-WAN creates the secure fabric tunnels between the Source Circuit to all the selected Destination Site Circuits.
    5. Click Save.
      You can view the created Secure Fabric Links on the Overlay Connections tab.