Configure an SD-WAN Topology Using the SD-WAN Wizard
The SD-WAN wizard allows you to easily configure VPN tunnels between your centralized headquarters and remote branch sites.
Before you begin
Ensure that you review Prerequisites for Using the SD-WAN Wizard and Guidelines and Limitations for Using SD-WAN Wizard.
Procedure
Step 1 | Choose Devices > Site To Site, and click Add. | ||
Step 2 | Enter a name for the SD-WAN VPN topology in the Topology Name field. | ||
Step 3 | Click the SD-WAN Topology radio button and click Create. | ||
Step 4 | Configure a hub: | ||
Step 5 | Configure spokes: Click Add Spoke to add a single spoke device, or click Add Spokes (Bulk Addition) to add multiple spokes to your topology.
For each spoke, the wizard automatically selects the hub's DVTI as the tunnel source IP address.
| ||
Step 6 | Configure authentication settings for the devices in the SD-WAN topology: | ||
Step 7 | Configure the SD-WAN settings: This step involves the auto generation of spoke tunnel interfaces, and BGP configuration of the overlay network. | ||
Step 8 | Click Finish to save and validate the SD-WAN topology. You can view the topology in the Site-to-Site VPN Summary page (Devices > Site-to-site VPN). After you deploy the configurations to all the devices, you can see the status of all the tunnels in this page. |
What to do next
-
View the auto-generated spoke SVTIs and their IP addresses—Click the edit icon next to the spoke configuration and click View Generated Tunnel Interfaces.
-
Deploy the configurations on the hub and spokes. Choose Deploy. Select devices and click Deploy.
-
Verify the SD-WAN topology tunnel statuses. For more information, see Verify Tunnel Statuses of an SD-WAN Topology.
-
Configure ACLs for the spokes' tunnel interface security zones. Choose Policies > Access Control.
-
For more information about configuration examples using SD-WAN wizard, see Sample Configurations for Dual ISP Deployment Using SD-WAN Wizard
-
Configure a PBR policy on each spoke for application-aware routing based on the application performance metrics of the WAN interfaces. For more information, see Route Application Traffic from the Branch to the Internet Using Direct Internet Access (DIA).