Send Traffic to Firewall for Inspection when ION is Data Center WAN Edge

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Send Traffic to Firewall for Inspection when ION is Data Center WAN Edge

L0 Member

Hi Prisma SD-WAN community,

 

I hope hope you are all keeping well.

 

I’m busy working on a Prisma SD-WAN proposal and architecture, and I’m trying to figure out how I would send traffic to a firewall in the DC for inspection first when the ION is the WAN edge. With the ION being the edge, it would simply just route the traffic out to the Internet, correct? PAN-OS’ Policy-Based Forwarding would work perfectly for this, and Prisma SD-WAN’s path policies seem to be the equivalent here, but the documentation doesn’t provide enough information and detail for me to confidently state that it can be used for this use case. Unfortunately, I have yet to deploy my first Prisma SD-WAN branch/DC, and I currently do not have access to any lab or POC equipment to test this.

 

 

Another option would be to use VRFs. Basically, all tunnels terminate on a Branch VRF with a default route to the firewall. The firewall then has a default route to an Internet VRF on the ION, but the Prisma SD-WAN VRF documentation again does not provide enough information and detail that such a configuration is supported.

 

How would you go about getting your traffic inspected when placing your ION at the edge of the DC to enjoy intelligent path selection? I attached my high level design as a visual aid.

 

Looking forward to your insight and input.

 

Prisma SD-WAN NGFW 

1 REPLY 1

L0 Member

Hi,
Does anyone know the answer to the above question?
I am also struggling to get the documentation for this.

  • 902 Views
  • 1 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!