| Where Can I Use This? | What Do I Need? |
Before you can begin configuring your
SD-WAN deployment, you must
first
install the SD-WAN plugin and add your hub
and branch firewalls as managed devices to the
Panorama® management server. As part of
adding your
SD-WAN firewall as a managed device on the
Panorama® management server, you must activate the Advanced
SD-WAN license
to enable
SD-WAN functionality for the firewall.
As part of adding your SD-WAN firewalls as managed devices, you must
configure your managed firewalls to forward logs to Panorama. Panorama collects information from multiple sources, such as configuration
logs, traffic logs, and link characteristic measurements, to generate the visibility
for SD-WAN application and link health information.
If your Panorama management server runs a version newer than PAN-OS® 10.1 (such
as PAN-OS 10.2) when you add a new device PAN-OS® 10.1 to SD-WAN cluster, the
commit-all operation fails. To ensure a successful push, your Panorama and
firewalls must run the same version for PAN-OS 10.1.x.
Do not have your Panorama management
server connection to be only reliant on the SD-WAN overlay. To
maintain a reliable connection, where the Panorama is always
reachable to the PAN-OS firewalls, we recommend you to create a dedicated IPSec
tunnel from the PAN-OS firewalls to reach Panorama (that is
outside the SD-WAN overlay between hub/branches where the
Panorama is
located). With this approach, you can ensure that the Panorama management
server is always reachable even if there is any impact to the SD-WAN
overlay.