| Where Can I Use This? | What Do I Need? |
Add a
SD-WAN hub or branch firewall to be managed by the
Panorama® management server. When adding your devices, you specify what type of device it
is (branch or hub) and you give each device its site name for easy identification.
Before adding your devices,
plan your SD-WAN configuration to ensure
that you have all the required IP addresses and you understand the
SD-WAN topology. This helps in reducing any configuration errors.
If you have preexisting zones for your Palo Alto Networks® firewalls, you
will be mapping them to the predefined zones used in SD-WAN.
If you want to have active/passive HA running on two branch firewalls or two hub
firewalls, don’t add those firewalls as
SD-WAN devices at this
time. You’ll add them as HA peers separately when you
configure SD-WAN devices in HA mode.
If you’re using BGP routing, you must add a Security policy rule to enable BGP
from the internal zone to the hub zone and from the hub zone to the internal
zone. If you want to use 4-byte ASNs, you must first enable 4-byte ASNs for the
virtual router.
When viewing
SD-WAN devices, if no data is present or the screen
indicates that
SD-WAN is undefined, check in the
Compatibility Matrix that the
Panorama release you’re using supports the
SD-WAN plugin
release you’re trying to use.