Skip to main content
HT_JDC
New Member
October 15, 2024
Solved

Loopback Address at SD-WAN

  • October 15, 2024
  • 2 replies
  • 1401 views

Hello Experts,

 

This may be a basic item.

Why is Loopback Address necessary at SD-WAN?

Is it used for SLA? If SLA is not important, can we omit it?

 

Thanks in advance,

 

Best answer by Toshi_Esumi

The SD-WAN itself shouldn't require a loopback interface/address on a FGT. But if you have set up two FGTs connected together over multiple VPNs and you put the multiple VPNs in an SD-WAN zone, you might want to set up a common interface/IP on the remote end to ping to with a performance SLA health-check rules so that the local end can measure which path/VPN is the best at a time in order to prefer that path.

My home FGT has SD-WAN for internet traffic steered but no VPNs to the other FGT is a member of a zone. So I don't have/need any loopback interface.

Toshi 

2 replies

Toshi_Esumi
SuperUser
SuperUser
October 16, 2024

The SD-WAN itself shouldn't require a loopback interface/address on a FGT. But if you have set up two FGTs connected together over multiple VPNs and you put the multiple VPNs in an SD-WAN zone, you might want to set up a common interface/IP on the remote end to ping to with a performance SLA health-check rules so that the local end can measure which path/VPN is the best at a time in order to prefer that path.

My home FGT has SD-WAN for internet traffic steered but no VPNs to the other FGT is a member of a zone. So I don't have/need any loopback interface.

Toshi 

HT_JDC
HT_JDCAuthor
New Member
October 16, 2024

Dear Toshi,

 

Thanks for your quick reply. I understood it.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!