Automated SD-WAN post overlay process creates policies to allow the health-checks traffic to flow between Branch and HUB
This information is also available in the FortiManager 7.4 Administration Guide: |
Automated SD-WAN post overlay process creates policies to allow the health-checks traffic to flow between Branch and HUB.
The SD-WAN overlay template includes two new options in the wizard to automate the post-wizard processes. The SD-WAN overlay template example configured in this document uses a dual-hub topology.
- Normalize Interfaces
Enable the Normalize Interfaces option to normalize the SD-WAN zones created by the template.- The following normalized interface is created for the SD-WAN Hub(s):
- HUB-Lo with Per-Device Mapping to HUB1-Lo for the HUB 1 device and HUB2-Lo from the HUB 2 device.
- HUB-Lo with Per-Device Mapping to HUB1-Lo for the HUB 1 device and HUB2-Lo from the HUB 2 device.
- The following normalized interfaces are created for branch devices:
- The HUB1 SD-WAN zone is mapped per-platform to HUB1.
- The HUB2 SD-WAN zone is mapped per-platform to HUB2.
- VPN IPsec tunnel templates are created for HUB interfaces when using the SD-WAN overlay template. When Normalized Interface is enabled, normalized interfaces for the VPNs are added to the normalized interface list.
- The HUB1 SD-WAN zone is mapped per-platform to HUB1.
- The following normalized interface is created for the SD-WAN Hub(s):
- Add Health Check Firewall Policy to Hub/Branch Policy Package
Enable the Add Health Check Firewall Policy to Hub/Branch Policy Package option to create health check firewall policies (or policy blocks) for HUB(s) and branches.- Users must select the HUB and branch policy package that will be used during the wizard configuration. You can select an existing policy package or create a new one.
- Based on the selection, firewall policies (or policy blocks) are created to allow SLA health checks to each device loopback.
- The SD-WAN overlay template creates the policy block and applies it to the top of the HUB Policy Package.
- A policy block is not created for the SD-WAN branch Policy Package.
- Users must select the HUB and branch policy package that will be used during the wizard configuration. You can select an existing policy package or create a new one.