| Where Can I Use This? | What Do I Need? |
- Prisma Access
- NGFW
- SD-WAN plugin 2.2
and
later versions
|
|
SD-WAN plugin 2.2
and later versions
provides
Prisma Access hub support, in which
PAN-OS firewalls connecting to
Prisma Access compute nodes (CNs)
achieve cloud-based security in an
SD-WAN hub-and-spoke topology. In
this topology, the
SD-WAN hubs are
Prisma Access CNs (IPSec
Termination Nodes) and the
SD-WAN branches are
PAN-OS
firewalls. A maximum of four hubs (any combination of
PAN-OS hubs
participating in DIA AnyPath and
Prisma Access hubs) are supported.
SD-WAN automatically creates IKE and IPSec tunnels that connect the
branch to the hub. Review the
system requirements for SD-WAN and Prisma
Access.
It's important to configure Prisma Access first, and then configure SD-WAN.
- If you're starting a brand new Prisma Access configuration, read the
Prisma Access Administrator’s
Guide and complete Phase 1 and then Phase 2 configuration
steps.
- If you already have Prisma Access running, ensure Phase 1 is complete,
and then complete Phase 2.
The following flowchart shows the order of the two configuration phases and basic
steps within each phase. The full Prisma Access prerequisites with links and the
configuration steps for SD-WAN follow the flowchart.
| PHASE 1—PRISMA ACCESS | PHASE 2—SD-WAN |
| (COMPLETE PHASE 1 FIRST) | (BEGIN ONLY AFTER
COMPLETING PHASE 1) |
- Set up the infrastructure subnet, infrastructure BGP AS,
template stack and device group for a tenant.
- Set up template stacks, templates, device groups, trust and
untrust zones, and bandwidth allocation for specific
regions.
- Ensure your Prisma Access deployment is licensed for
remote networks.
- Ensure your deployment allocates bandwidth per compute
location, instead of by location.
- Ensure you have assigned bandwidth to the compute location
that corresponds to the location to which you want to
onboard.
- Perform a local commit and push to the Prisma Access
cloud.
|
- Configure a branch firewall with an interface that has SD-WAN enabled.
- Log in to the Panorama web interface.
- Specify the BGP local address pool for loopback
addresses.
- Select the SD-WAN branch firewall to connect
to the Prisma Access hub and configure the
connection.
- Commit and Push the configuration to the cloud.
- Verify that onboarding is complete.
- Synchronize the branch firewall to Prisma Access.
- Commit to Panorama.
- Push to Devices.
- View the new interface that was created.
- Verify the IPSec tunnel is up.
- Verify the IKE gateway is up.
- Create an SD-WAN policy rule to generate
monitoring data.
- Commit and Commit and Push to branch firewalls.
- Monitor Prisma Access hub application and link
performance.
|
Before you connect
SD-WAN to
Prisma Access, you must have a branch
firewall with an interface that has
SD-WAN enabled. Additionally,
ensure you have performed the following
Prisma Access prerequisites for one or
more tenants; these are the Phase 1 steps:
- For , set up the infrastructure subnet, infrastructure BGP AS,
template stack and device group for a tenant on the Service
Setup page.
- On the Remote Networks page, set up template stacks,
templates, device groups, trust and untrust zones, and bandwidth allocation for
specific regions.
- Ensure your Prisma Access deployment is
licensed for remote networks by
selecting and checking your license information.
- Licenses available after November 17, 2020 show the amount of licensed
bandwidth you have for remote networks in the Net
Capacity area.
- Licenses available before November 17, 2020 show the available remote
network bandwidth in the GlobalProtect Cloud Service for
Remote Networks area under Total
Mbps.
- Ensure your deployment allocates bandwidth per compute
location, instead of by location.
Ensure you have assigned bandwidth to the compute location that
corresponds to the location to
which you want to onboard.
Prisma Access allocates one IPSec termination
node per 500 Mbps of bandwidth you allocate to a region.
- Perform a local commit and push to the Prisma Access cloud.
After you have performed the preceding steps for Phase 1 with Prisma Access,
perform the following Phase 2 steps for SD-WAN.