JunaidKhan Lv1Posted 26 Sep 2023 14:28
  
Short question: When using SD-WAN for multiple ISPs, is there a way to leverage the SD-WAN interface for VPNs? (Instead of selecting each physical interface for VPNs)
Long version: When our clients have a few sites with 2 ISPs each, setting up all the tunnels becomes a burden. In my experience the best way to ensure everything works solidly is to manually setup multiple tunnels.
The following diagram shows a common scenario. Sites 1 and 2 are larger sites that have redundant internet connections, site 3 is smaller and will get a second connection when the business requires it (we always use SD-WAN even on single links so that it's easy to grow).





Currently we are manually setting up multiple tunnels. We then put all the tunnels into the same zone and use the zone to apply a common set of policies to all the tunnels. Depending on the needs we will sometimes use OSPF, but more commonly we just use equal-cost routes. As I mentioned before this takes a lot of time to setup properly!
If we could leveraging the SD-WAN interface for the VPN the setup would be greatly simplified. Is there a way to use the SD-WAN virtual interface for a VPN, instead of choosing the physical interface?

123.png (4.59 KB, Downloads: 443)

123.png

I Can Help:

Change

Moderator on This Board

0
1
0

Started Topics

Followers

Follow

Trending Topics

Board Leaders