1. Introduction
This Administration Guide describes how to configure and operate Check Point SD-WAN with Smart-1 Unified Management.
In this management model, SD-WAN configuration and SD-WAN Policy are managed from Smart-1 Management by using SmartConsole.
The guide is organized as a deployment workflow. It starts with Security Gateway networking, continues with SmartConsole configuration, and ends with policy installation, validation, and troubleshooting.
1.1 Management Architecture
In Smart-1 Unified Management, the management path is:
Management Server -> SD-WAN process on the Security Gateway -> Steering / Firewall / SecureXL on the Security Gateway
The SD-WAN configuration is stored and installed from Management Server. The Security Gateway enforces the installed SD-WAN Policy on the SD-WAN steering process and the Firewall.
1.2 Introduction to SD-WAN
With SD-WAN you can configure your Security Gateway / Cluster to steer traffic dynamically between the configured WAN Links based on the measured ISP link quality. This does not require dynamic routing configuration on your Security Gateway / Cluster.
With SD-WAN customers get the most efficient use of high-cost Wide Area Network connections and best user experience for consuming cloud-hosted services in branch offices.
The Security Gateway / Cluster sends different types of traffic through different Internet Service Providers (ISPs) based on application / identity and dynamic measurement of WAN Link characteristics.
The Security Gateway / Cluster applies the configured SD-WAN rules only if the Security Policy allows this traffic.
After you install the SD-WAN Policy, it becomes the main decision maker for traffic paths, traffic priorities, and so on for WAN connections. The SD-WAN Policy makes these decisions based on the settings you configure in SD-WAN Policy in SmartConsole.
For additional information, see sk185141.
SD-WAN Use Case
A Security Gateway is connected to two Internet Service Providers.
Traffic from the Zoom application goes to the Internet through ISP #1.
Traffic from the Outlook 365 application goes to the Internet through ISP #2.
Basic SD-WAN Action
You can use SD-WAN for:
-
Local Breakout - to control the steering and select the best path for outbound traffic to the Internet.
-
- to control the best VPN path between VPN peers, for routing internal traffic between the organization sites, either from VPN Spokes to the Hub (Satellites to Center), or between VPN sites in a mesh topology.
-
Backhaul - to route Internet traffic on VPN spoke sites through the Headquarters over the VPN tunnel. This connection uses the overlay-based connection from the Branch to the Center, and a Breakout-based connection from the Center to the Internet.
The Security Gateway uses the WAN Links you configured as SD-WAN interfaces, for Breakout (public SD-WAN interfaces) and for VPN (all SD-WAN interfaces).
SD-WAN Policy
The SD-WAN Policy contains ordered rules to classification of traffic:
-
Source and Destination - IP address, Network address, User / Computer Identity.
-
Service or Application - Zoom, Teams, HTTPS, FTP (see the supported objects in 8. Configure the SD-WAN Policy).
|
|
Note - The Security Gateway uses these heuristics to identify connections on the first packet:
|
As a result of these multiple heuristics, the Security Gateway might not detect the application on the first packet of its connection. For example, when two applications are hosted on the same server.
|
|
Best Practice - Use Updatable Objects in the "Destination" column of the SD-WAN Policy. This allows matching of application connections on the first packet and most accurate traffic steering. |
Example of an SD-WAN Policy
|
# |
Name |
Source |
Destination |
Services & Applications |
Behavior |
|---|---|---|---|---|---|
|
1 |
Teams |
Net_192.168.20.0 |
|
|
Aggregate |
|
2 |
Zoom |
Net_192.168.20.0 |
|
|
Prioritize_WAN2 |
|
3 |
YouTube for Sales |
SalesRole |
|
|
High_Quality |
-
Rule #1:
For all traffic from the network 192.168.20.0/24 to the Internet, from the application with the signature of Microsoft Teams, apply the steering behavior "Aggregate".
-
Rule #2:
For all traffic from the network 192.168.20.0/24 to IP addresses that are resolved from the Updatable object "Zoom Services", from any application, apply the steering behavior "Prioritize_WAN2".
-
Rule #3:
For all traffic from users (IP addresses) determined by the Access Role "SalesRole" to the Internet, from the application with the signature of "YouTube", apply the steering behavior "High_Quality".
1.3 Administration Guide Scope
This Administration Guide describes how to configure and operate Check Point SD-WAN with Smart-1 Unified Management in SmartConsole.
This guide covers:
-
Enable SD-WAN object availability on the Smart-1 Management Server before starting SmartConsole configuration.
-
Plan the SD-WAN deployment, including requirements, licensing, supported deployments, R82.20 EA scope, and known limitations.
-
Prepare Security Gateway networking, including interfaces, routing, ISP next hops, route monitoring, and management connectivity.
-
Configure SD-WAN objects in SmartConsole, including Circuits, WAN Links, Steering objects, NAT objects, QoS profiles, DSCP objects, and SD-WAN Dynamic Objects.
-
Enable the SD-WAN blade on Security Gateway and Cluster objects.
-
Configure SD-WAN settings on Security Gateway interfaces, including Network Access settings, Next Hop Mode, Circuit association, NAT settings, WAN Link mapping, bandwidth, QoS enablement, and Symmetric Return.
-
Create and install the shared SD-WAN Policy.
-
Configure Local Breakout, Backhaul, Prioritize Local Breakout, and use cases.
-
Configure VPN and Access Control requirements for and Backhaul, including Site-to-Site VPN Communities, Link Selection for non-SD-WAN peers, probing rules, Route-Based VPN, and Backhaul NAT requirements.
-
Configure advanced SD-WAN features where supported or documented for R82.20 GA readiness, including NAT per ISP, QoS, DSCP, Forward Error Correction, DAIP, IPv6, Layer 2 , ECMP, Symmetric Overlay Return, Automatic Next Hop, and SD-WAN steering parameters.
-
Monitor SD-WAN behavior with SmartConsole logs, SD-WAN events, dashboards, and Security Gateway CLI commands.
-
Validate and troubleshoot SD-WAN Policy installation, rule matching, Local Breakout, , Backhaul, NAT, QoS, FEC, Auto Next Hop, and kernel debug flows.
-
Perform operational tasks such as migration from Portal Application Management, rollback, disabling SD-WAN, and using CLI reference commands.
1.4 Terminology
|
Term |
Meaning in this guide |
|---|---|
|
Check Point SD-WAN |
The product name used throughout this guide. |
|
Smart-1 Unified Management |
The SD-WAN management model where SD-WAN objects, Security Gateway settings, and SD-WAN Policy are managed in SmartConsole connected to a Management Server. |
|
Portal Application Management |
The legacy Portal-based SD-WAN management model. It is mentioned only where required for migration context. |
|
SDWAN process |
The process on the Security Gateway responsible for SD-WAN Policy installation and orchestration. |
|
sdwan_steering |
The main steering engine process on the Security Gateway. |
|
Circuit |
An object that represents a WAN domain used to control which peer interfaces can form overlay connectivity. |
|
WAN Link |
An SD-WAN object mapped to a Security Gateway interface. WAN Links can be public (Internet) or private (MPLS). |