Configure Internet Ports
Focus
Focus
Prisma SD-WAN

Configure Internet Ports

Table of Contents
Let us learn to configure internet ports. Ports are the physical interfaces on the ION device and Interfaces are the logical interfaces on the ION device.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN
  • Prisma SD-WAN license
  1. From internet ports, select a port pair.
  2. In the General section,
    1. Enter a Name and Optional Description, and add Tags for the port channel interface.
    2. For Admin Up, select Up.
  3. In the Network Setting section,
    1. For Interface Type, select Port.
    2. For Use these Ports For, select Internet.
      Alternatively, you can select Private WAN for Use these Ports For to configure a WAN port for a Private WAN circuit.
    3. For Scope, toggle Local or Global.
      The default is Local.
      If the scope is local, the route is not advertised to the data center.
      If the scope is global, the route is advertised to the data center.
      • This setting is applicable only to branch sites. It is not applicable to data center sites.
      • Configuring a global static route will advertise the destination IP/prefix to other sites automatically.
    4. For Circuit Label, select the circuit label that corresponds to your internet connection for this site.
    5. For IPv4 Configuration, select DHCP or Static.
      Choose DHCP if the IP address is dynamically assigned.
      Choose Static if the IP address is fixed and is manually assigned. Additionally specify the IP Address/Mask, Default Gateway, and DNS server(s).
    6. Select Enable IPv6 On This Interface to configure IPv6.
    7. For IPv6 Configuration, select AutoConf or Static.
      Autoconf indicates the Global IP address is derived using stateless address autoconfiguration (SLAAC).
      Choose Static if the IP address is fixed and is manually assigned. Additionally specify the IPv6 Address/Mask, Default Gateway (IPv6), and DNS server(s)(IPv6).
  4. In Advanced Options, optional specify MAC, IP MTU, External NAT Address and Port (IPv4), External NAT Address and Port (IPv6),and Physical from the available range.
    IP MTU value should be at least 1280 for IPv6. If it is less than 1280, IPv6 cannot be enabled.
  5. Click Save.
    The ION device inherently hardens all the ports designated as Internet. You can access only UDP 4500, 500 (ISAKMP), and ESP ports. The utilization of UDP port 500 (ISAKMP) is exclusively reserved for standard VPNs. Configure the ports accordingly to avoid automatic rejection of requests. The ION device blocks any unsolicited incoming internet traffic.