cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Send Traffic to Firewall for Inspection when ION is Data Center WAN Edge

L0 Member

Hi Prisma SD-WAN community,

 

I hope hope you are all keeping well.

 

I’m busy working on a Prisma SD-WAN proposal and architecture, and I’m trying to figure out how I would send traffic to a firewall in the DC for inspection first when the ION is the WAN edge. With the ION being the edge, it would simply just route the traffic out to the Internet, correct? PAN-OS’ Policy-Based Forwarding would work perfectly for this, and Prisma SD-WAN’s path policies seem to be the equivalent here, but the documentation doesn’t provide enough information and detail for me to confidently state that it can be used for this use case. Unfortunately, I have yet to deploy my first Prisma SD-WAN branch/DC, and I currently do not have access to any lab or POC equipment to test this.

 

 

Another option would be to use VRFs. Basically, all tunnels terminate on a Branch VRF with a default route to the firewall. The firewall then has a default route to an Internet VRF on the ION, but the Prisma SD-WAN VRF documentation again does not provide enough information and detail that such a configuration is supported.

 

How would you go about getting your traffic inspected when placing your ION at the edge of the DC to enjoy intelligent path selection? I attached my high level design as a visual aid.

 

Looking forward to your insight and input.

 

Prisma SD-WAN NGFW 

Who rated this post