Configure Data Center (DC-DC) Interconnectivity
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Configure Branch HA in a Hybrid Topology with Gen-1 (3000) and Gen-2 (3200) Platforms
- Prisma SD-WAN Incidents and Alerts
Configure Data Center (DC-DC) Interconnectivity
Prisma SD-WAN ION data center devices can communicate each other using
standard VPN IPsec tunnels. Learn how to configure DC-DC tunnels in Prisma SD-WAN.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Prisma SD-WAN supports standard VPN for connection between
two Data Center ION devices. Both the DC ION devices may try to initiate a tunnel,
in which case, the tunnel will not be established. To overcome this issue, Prisma SD-WAN supports the responder-only mode for the DC ION
devices, so that the ION device only responds to the IKE connection and does not
initiate it.
Prisma SD-WAN currently supports this
feature only for IPsec VPNs and not for GRE VPNs. Prisma SD-WAN
supports both IKEv1 and IKEv2.
- Select ManageWorkflowsDevicesClaimed Devices.From the ellipsis menu, select Configure the device.On the Configure Interface: New Standard VPN screen, set up the Main Configuration for the new interface.
- For Admin Up, select Yes.(Optional) Enter a Name, Description, and Tags.Select IPsec as the Standard VPN Type.The Interface Type must display as Standard VPN.Select a Parent Interface to establish the GRE tunnel.For a data center ION device, any of the following ports can be used as a parent interface:
- Any Connect to Internet port
- Any Connect to Peer Network port
Toggle Scope to Local or Global.Enter an Inner Tunnel IP Address or Mask.For the Endpoint name, add the name of the connected Data Center site.Note that although configured, the Endpoint will not be pushed to the DC ION device, since the Endpoint applies only for a branch ION device. Hence, you have to enter a Peer IP for the tunnel to be established.Enter a Peer IP of the connected DC site.The Peer IP is mandatory for a DC-DC tunnel.Select an IPsec Profile.Select a created IPsec profile.Under Advanced Options, navigate to Passive Mode.By default, Passive Mode is No, which means that the device can act as a responder and an initiator.(Optional) Select Yes for Passive Modeto have the ION device in the responder-only mode. Set one end of the tunnel to Yes and the other end to No.Click Create Standard VPN.You can view the DC-DC tunnels on the Overlays Connection page for a DC site.Port Translation between Data CentersIf one of the ION devices is behind a NAT device, you need to configure an inbound DNAT rule for port translation for the receiving ION device, so that port 4500 is translated to port 4501 for a given IP address.