Skip to main content
phowardmhm
New Member
October 15, 2019
Question

Interfaces with SD-WAN setup

  • October 15, 2019
  • 3 replies
  • 4722 views

Hello,

     I have a customer that has added another internet connection to the firewall and I want to build out SD-WAN with failover.  I get the setup part but how do I deal with the interfaces.  What do I do with all tunnels off the interface?  

3 replies

sw2090
SuperUser
SuperUser
October 16, 2019

VPN Tunnels and I guess also vlans on the wan interfaces are not affected by sdwan. They still use the physical interface.  I just can't say for sure concernign vlans as I don't have vlans on the wan interfaces here. You will just have to replace your wan interfaces by the sdwan interface in your internet policies.

phowardmhm
New Member
October 16, 2019

Thanks for the comment.

 

This had been built out by someone else and quite a while ago so looking at this more I've decided to essentially peel everything off WAN1 and rebuild it out with the SD-WAN.  It has a secondary internet connection being feed via WAN1 along with the primary internet connection so that doesn't really give me the redundancy I'm looking for.

 

With configurations that have two ISPs w/ VPN tunnels and no SD-WAN I would have a tunnel off WAN1 and "backup" tunnel off WAN2 so would I not need both with SD-WAN?  One VPN tunnel for the SD-WAN interface?

sw2090
SuperUser
SuperUser
October 17, 2019

At least IPSEC cannot use a dynamic interface because you must give a specific remote gw on the tunnel's opposite end. You could only have one FQDN per interface in sdwan. Sdwan itself is not an option here because it depends on your rules and setings which interface in sdwan is used at which time. If you used FQDN on SDWAN as remote gw this would cause a load of drop outs or Flickering on the tunnels I guess.

I however prefer having one tunnel per wan for redundancy. I cope this with priority based routing. this works fine, has defined ends for remote gw and  does tunnel fallback when the primary wan goes down to the second tunnel and back again.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!