Add a Branch Gateway
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Configure Branch HA in a Hybrid Topology with Gen-1 (3000) and Gen-2 (3200) Platforms
- Prisma SD-WAN Incidents and Alerts
Add a Branch Gateway
Prisma SD-WAN offers a new hybrid site type, which is the branch
gateway site to maximize the flexibility of the system.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Geographically distributed organizations often have smaller regional datacenters
colocated with users, manufacturing, and other business operations presenting both
configuration and operations challenges. The single-click capability to create
Regional Branch Gateways simplifies the adoption of this use case by automatically
creating VPN topologies and instantiating Hub (Policy Transit, LQM Server, etc )
& Branch (App visibility, path selection, etc) services to simplify Day 1 and
Day 2 operations for all traffic types and vectors.
You can enable the branch gateway functionality with a single click of the site level
configuration setting. Upon enabling the branch gateway mode, VPN tunnels will
automatically form between the branch gateway site and corresponding branch sites in
the domain.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Prisma SD-WAN supports branch gateway sites on the following
platforms:
- ION 3200
- ION 5200
- ION 9200
- ION 3000
- ION 7000
- ION 9000
All virtual ION models also support a branch gateway site.
The ION device assigned to a branch gateway site supports the following
interfaces:
- Port
- Bypass Pair
- Subinterfaces
- Virtual Interfaces
- Standard VPN
Interfaces in the branch gateway site support IPv4 & IPv6 static and DHCP
addresses as well as secondary addresses.
You can create a new site as a branch gateway site or can convert an existing branch
site to a branch gateway site after completing the site configuration.
- Create a new branch gateway site.
- Select WorkflowsBranch SitesAdd Site.Add a Site Name and optionally enter description and tags.Enable Configure as a Branch Gateway Site.Add the other details to set up a site and click Save & Exit.Assign a device to the created branch gateway site, enable L3 Direct Private WAN Forwarding and L3 LAN Forwarding for the device and then configure the interfaces.Convert an existing branch site to a branch gateway site.You can convert an existing branch site to a branch gateway site.Ensure that:
- The site is in Control mode.
- You have enabled L3 Direct Private WAN Forwarding.
- You have enabled L3 LAN Forwarding.
- There are no any existing branch-to-branch VPN tunnels. If any tunnels exist, Prisma SD-WAN deletes them during the conversion process.
- Select WorkflowsBranch Sites and click the ellipsis menu for the site.Select Switch to Branch Gateway Site.Switching a branch site to a branch gateway site causes the ION device to reboot.Alternatively, you can select Branch Sites, then select a site and then enable Branch Gateway.Edit branch gateway site settings.(Optional) After you create a branch gateway site, you can optionally edit the branch gateway site settings.Select Prefer LAN Default over WAN in case your topology needs to take the LAN interface (with a default gateway) as the default route. This will mimic the path selection behavior of a data center site where the device forwards all incoming WAN traffic to the LAN peer.For example, if the traffic flow is — Branch ↔Branch Gateway ↔ LAN (Firewall → Internet). Typically, the ION device will have a default route (0.0.0.0/0) on the internet (WAN) interfaces (with the next hop as the default gateway configured on the wan interface or from DHCP). This is to steer packets to the internet (for DIA or otherwise) if no other specific route exists. In this particular scenario, the branch gateway site needs to take the LAN interface. The LAN interface has a default gateway configured either statically or via DHCP as a default route as against an internet interface, which would generally have a default route. You can achieve this by adding a default route with a lower admin cost on the LAN interface than the WAN interface when you select Prefer LAN Default over WAN.Maximum Branch Site Count Info indicates the maximum number of branch sites that you can associate with a branch gateway site. If you exceed this number, Prisma SD-WAN generates an incident. However, it will still be possible to associate branches to the branch gateway by joining the domain or through the establishment of manual tunnels.Create VPNs between branch gateway sites or branch sites.Prisma SD-WAN establishes VPN tunnels as follows:
- Branch -> Branch Gateway (Same Domain) — Prisma SD-WANautomatically builds Fabric VPN tunnels.
- Branch -> Branch Gateway (Different Domain) — You need to manually configure Fabric VPN Tunnels.
- Branch Gateway -> DC — Prisma SD-WAN automatically builds VPN tunnels.
- Branch Gateway -> Branch Gateway — You need to manually configure Fabric VPN Tunnels.
- (Optional) Changing the domain of a branch gateway site.
- Select a branch gateway site.
- Click the ellipsis menu and select Change Site Domain.
- Choose the required domain and click Submit.
To establish an automatic VPN tunnel between a branch site and a branch gateway site, ensure that both are in the same domain.(Optional) Create a manual VPN tunnel between two branch gateway sites.- Select WorkflowsSites and select a branch gateway site.
- Select Overlay ConnectionsBranch Gateway — Branch GatewayAdd Link.
- Select a circuit and select the site for VPN establishment on the Add Secure Fabric Link pop-up.
Prefix AdvertisementThe branch gateway site performs prefix advertisement and distribution in a variety of topologies.Prefix Advertisement Learned Via Advertised To Fabric Tunnel LAN BGP PeerStandard VPN BGP PeerStandard VPN Tunnel BGP Peer Fabric (to branch)LAN BGP PeerLAN BGP Peer Fabric → yesLAN BGP Peer → yesPrivate WAN BGP Peer → yesPrivate WAN BGP Peer LAN BGP Peer → yes LAN Static Route Fabric → yesLAN BGP Peer → yesPrivate WAN BGP Peer → yesDefault Route in WAN BGP Peer.Prisma SD-WAN has enhanced the existing BGP Global configuration to allow an option to choose the default route as part of the prefix advertisement to WAN.For a BGP peer, select Advertise Default Route to Peer to distribute the default route to the peer, instead of explicitly configuring a prefix via route-maps.