| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by PAN-OS or Panorama)
- NGFW (Managed by Strata Cloud Manager)
|
|
Enable
SD-WAN functionality to configure a physical,
Layer 3 Ethernet interface.
To configure a physical interface, you must assign it an:
- (Panorama) IPv4, or IPv6 address, or both
- (Strata Cloud Manager) IPv4 address
You must also assign the interface a fully qualified next-hop
gateway and assign an
SD-WAN interface profile to the
interface.
SD-WAN supports only a Layer 3 interface type; it doesn't
support Layer 2 networks such as
VPLS. The
SD-WAN interface profile defines key characteristics that the
firewall uses to manage that specific physical link, such as the link type (ADSL,
cable modem, MPLS), maximum upload and download speeds, and path monitoring
settings. By associating an
SD-WAN interface profile with a physical
Ethernet interface, you're essentially telling the firewall how to treat that
specific connection within the
SD-WAN environment. This association
allows the firewall to apply the appropriate settings for link management, failover
behavior, and traffic routing based on the profile's
configuration.
(Panorama)
After you
create
a VPN cluster and export your hub and branch information in the CSV, an Auto VPN
configuration in the SD-WAN plugin uses this information to generate
a configuration for the associated branches and hubs that includes the predefined
SD-WAN zones and creates secure VPN tunnels between SD-WAN branches and hubs. Auto VPN configuration also generates the
BGP configuration if you enter BGP information in the CSV
or
when you add an SD-WAN branch or hub.
(Strata Cloud Manager) BGP routing is enabled and generated by default.