Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology

L1 Bithead

Hi

I am new to PAN-OS SD-WAN and need to clarify Internet service requirement at new spoke site.

 

My client has PAN-OS SD-WAN hub-and-spoke topology, the hub PA firewall has a static public IP for its internet service.

All spoke PA firewalls also use static public IPs, but we now will have a new spoke with a dynamic public IP.

 

I am hoping to confirm my understanding is correct - 

  1. In a hub/spoke topology, spoke firewalls always initiate the IPsec tunnel to the hub. (Hub never initiate tunnels to spoke)
  2. Therefore, new spoke with a dynamic IP should be able to connect to the hub and join the SD-WAN cluster without requiring DDNS on its interface.
  3. Based on the admin guide below, it states "Using DHCP on a hub requires the Palo Alto Networks DDNS service". so I assume DHCP on a branch doesn't require DDNS service.

 

From Admin guide - 

Although DHCP Client is supported for a hub or branch interface, on a hub interface it’s preferable for you to assign a Static address instead of DHCP Client. Using DHCP on a hub requires the Palo Alto Networks DDNS service. Using a Static address at the hub site creates a more stable environment because DDNS isn’t involved when resolving the DHCP IP address changes, and because the DDNS service can take a few minutes to register the new IP address when it changes. If you have multiple branch sites connecting to a hub site, having stability is critical to keeping the network up and running.

 

1 REPLY 1

Cyber Elite
Cyber Elite

@ahwang2929,

That is correct, using a dynamic IP on a spoke isn't any concern in a hub-spoke topology. It would create an issue if you were using a mesh deployment, but outside of that it won't matter. 

  • 58 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!