SDWAN Zone Mapping

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
Jeff-Intuitive
L1 Bithead

SDWAN Zone Mapping

Trying to make sure I understand this correctly.  For each zone to used within the SDWAN they must be mapped to the pre-defined SDWAN zones.  For the following example would this be the correct method of mapping:

 

Pre-SDWAN zones (same zones at all sites)

Untrust

Private WAN

Trust-1

Trust-2

Trust-3

 

SDWAN Zone Mapping

Zone Internet: Untrust Trust-1, Trust-2,Trust-3

Zone to Hub: Trust-1, Trust-2,Trust-3

Zone to Branch: Trust-1, Trust-2,Trust-3

Zone Internal: Trust-1, Trust-2,Trust-3

Tags (1)
kiwi
Community Team Member

Hi @Jeff-Intuitive ,

 

I'm pretty sure that Untrust will map to Zone Internet only.

 

Depending on the other access you need :

  • Zone Internet—For traffic going to and coming from the untrusted internet.
  • Zone to Hub—For traffic going from branch firewalls to hub firewalls and for traffic going between hub firewalls.
  • Zone to Branch—For traffic going from hub firewalls to branch firewalls and for traffic between branch firewalls.
  • Zone Internal—For internal traffic at a specific location.

 

Cheers,

-Kiwi.

 
Jeff-Intuitive
L1 Bithead

that is what we learned as well, thanks for that.  The interesting thing is the plugin requires us to hand type, not select, the zones.  If you don't map all the zones though it does not work and it doesn't replicated the configuration across a HA pair, had to manually do both nodes.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!