Fortinet white logo
Fortinet white logo

SD-WAN Deployment for MSSPs

Configuring Edge devices with SD-WAN

Configuring Edge devices with SD-WAN

As can be seen, no configuration change was required on the Edge devices when switching from a single-regional to a multi-regional deployment.

The Edge devices do not require any configuration related to the remote regions. They only learn the route summaries from the remote regions, which allows them to send traffic via their local Hubs.

The same is true for SD-WAN configuration. The overlay selection is done locally by the originating Edge device, and the overlay stickiness policy routes on the Hubs ensure that this selection is preserved end-to-end.

Note

Depending on the requirements and on the nature of the inter-regional communication, more complex deployments may be possible. These include, but are not limited to:

  • Using SD-WAN rules on the Hubs to select the best path towards the remote Hub, rather than extending the overlay stickiness policy across the regions. This implies that the type of the overlay might change along the path, if the network conditions justify that.
  • Extending ADVPN across the regions to allow direct ADVPN shortcuts between the Edge devices from different regions. Note that this feature significantly complicates the routing design, and hence it must be used with care.

These types of deployment are outside the scope of this document.

Configuring Edge devices with SD-WAN

Configuring Edge devices with SD-WAN

As can be seen, no configuration change was required on the Edge devices when switching from a single-regional to a multi-regional deployment.

The Edge devices do not require any configuration related to the remote regions. They only learn the route summaries from the remote regions, which allows them to send traffic via their local Hubs.

The same is true for SD-WAN configuration. The overlay selection is done locally by the originating Edge device, and the overlay stickiness policy routes on the Hubs ensure that this selection is preserved end-to-end.

Note

Depending on the requirements and on the nature of the inter-regional communication, more complex deployments may be possible. These include, but are not limited to:

  • Using SD-WAN rules on the Hubs to select the best path towards the remote Hub, rather than extending the overlay stickiness policy across the regions. This implies that the type of the overlay might change along the path, if the network conditions justify that.
  • Extending ADVPN across the regions to allow direct ADVPN shortcuts between the Edge devices from different regions. Note that this feature significantly complicates the routing design, and hence it must be used with care.

These types of deployment are outside the scope of this document.