4. Prepare Security Gateway Networking

Before configuring SD-WAN in SmartConsole, configure the required networking on the Security Gateway. SD-WAN uses the Security Gateway interfaces and the routing table as the foundation for WAN link selection and management connectivity.

4.1 Configuring Interfaces in the Gaia Operating System

Configure all required physical interfaces, VLAN interfaces, IP addresses, and subnet masks on the Security Gateway.

The Security Gateway must have a valid routing table for its own connectivity.

Example topology:

  • The interfaces eth1, eth2, and eth3 are connected to Internet Service Providers.

  • The interface eth4 is the internal LAN interface.

set interface eth1 state on

set interface eth1 ipv4-address 198.51.100.254 mask-length 24

set interface eth2 state on

set interface eth2 ipv4-address 203.0.113.254 mask-length 24

set interface eth3 state on

set interface eth3 ipv4-address 192.168.251.254 mask-length 24

set interface eth4 state on

set interface eth4 ipv4-address 10.1.30.254 mask-length 24

save config

4.2 Configuring Default Routes through ISP Next Hops in the Gaia Operating System

Configure a different default route through each ISP next hop.

Use different priorities so that the Security Gateway has a deterministic active route for its own originated traffic.

set static-route default nexthop gateway address 198.51.100.1 on

set static-route default nexthop gateway address 203.0.113.1 priority 1 on

set static-route default nexthop gateway address 192.168.251.1 priority 2 on

set static-route default ping on

save config

Important - Lower priority number has higher preference. If no priority is configured, the route uses priority 0, which has the highest preference.

Note - These routes will also be used by the Automatic Next Hop feature that you configure in Security Gateway object at the interface level.

Best Practice - Enable next-hop monitoring, such as ping on, and consider IP Reachability Detection so that a route remains active only when the path is reachable.

  • Choose one or more dedicated monitoring targets as the number of your ISPs.

  • Set static route for each monitoring target to get routed through the monitored ISP only.

  • Attach the monitoring targets to the ISP routes.

  • Do not attach monitoring targets to the last-resort ISP route (the route with the lowest preference).

Configuration example for properly configured IP Reachability detection:

set ip-reachability-detection ping address 1.1.1.1 enable-ping on

set ip-reachability-detection ping address 9.9.9.9 enable-ping on

set static-route 1.1.1.1/32 nexthop gateway address 198.51.100.1 on

set static-route 9.9.9.9/32 nexthop gateway address 203.0.113.1 on

set static-route default nexthop gateway address 198.51.100.1 on

set static-route default nexthop gateway address 198.51.100.1 monitored-ip 1.1.1.1 on

set static-route default nexthop gateway address 203.0.113.1 priority 1 on

set static-route default nexthop gateway address 203.0.113.1 monitored-ip 9.9.9.9 on

set static-route default nexthop gateway address 192.168.251.1 priority 2 on

save config

4.3 Configuring Spark Firewall

For Spark Firewall appliances, configure the Internet connection settings. Select the connection type, configure the IP address, subnet mask, default gateway (unless you use a connection with a Dynamic IP address), and connection monitoring.

4.4 Connecting a Security Gateway to the Management Server

The Security Gateway initiates connections to its Management Servers for operations such as fetching the policy, retrieving CRL, and sending logs. To allow the Security Gateway to use all relevant external interfaces for connectivity to the Management Server, the Security Gateway's routing table must provide a valid route to the Management Server through each required path.

If the Management Server is reachable through the Internet, configure a route to the Management Server, or a default route, through each relevant ISP next hop.

If the Management Server is reachable only through MPLS or another private network, configure the required route through the relevant private path.

Best Practice - Monitor the next hop for each management path, so that the Security Gateway can fail over to another available path when the active path fails.

4.5 Management-Initiated Policy Installation Connectivity

When the Management Server installs policy, it initiates a connection to the Security Gateway.

In Smart-1 Unified Management deployments, the Management Server can use the IP addresses configured on SD-WAN interfaces in the Security Gateway object, if the main management IP address is unreachable.

The Management Server tries the configured IP addresses on SD-WAN interfaces one by one.

If the Management Server fails to establish a TCP connection with first IP address, it tries the next IP address until the connection succeeds or all configured IP addresses on SD-WAN interfaces were tried.

Note - The return traffic will return symmetrically from the same external interface for SD-WAN interfaces where Symmetric Return is enabled (this is the default).

Important - The Management Server attempts policy installation only through the IP addresses configured on SD-WAN interfaces in the Security Gateway object. If the interface is behind NAT, this fallback does not initiate the connection to the translated NAT IP address.