4. Prepare Security Gateway Networking
Before configuring SD-WAN in SmartConsole, configure the required networking on the Security Gateway. SD-WAN uses the Security Gateway interfaces and the routing table as the foundation for WAN link selection and management connectivity.
4.1 Configuring Interfaces in the Gaia Operating System
Configure all required physical interfaces, VLAN interfaces, IP addresses, and subnet masks on the Security Gateway.
The Security Gateway must have a valid routing table for its own connectivity.
Example topology:
-
The interfaces
eth1,eth2, andeth3are connected to Internet Service Providers. -
The interface
eth4is the internal LAN interface.
|
|
4.2 Configuring Default Routes through ISP Next Hops in the Gaia Operating System
Configure a different default route through each ISP next hop.
Use different priorities so that the Security Gateway has a deterministic active route for its own originated traffic.
|
|
|
|
Important - Lower priority number has higher preference. If no priority is configured, the route uses priority 0, which has the highest preference. |
|
|
Note - These routes will also be used by the Automatic Next Hop feature that you configure in Security Gateway object at the interface level. |
|
|
Best Practice - Enable next-hop monitoring, such as ping on, and consider IP Reachability Detection so that a route remains active only when the path is reachable.
|
Configuration example for properly configured IP Reachability detection:
|
|
4.3 Configuring Spark Firewall
For Spark Firewall appliances, configure the Internet connection settings. Select the connection type, configure the IP address, subnet mask, default gateway (unless you use a connection with a Dynamic IP address), and connection monitoring.
4.4 Connecting a Security Gateway to the Management Server
The Security Gateway initiates connections to its Management Servers for operations such as fetching the policy, retrieving CRL, and sending logs. To allow the Security Gateway to use all relevant external interfaces for connectivity to the Management Server, the Security Gateway's routing table must provide a valid route to the Management Server through each required path.
If the Management Server is reachable through the Internet, configure a route to the Management Server, or a default route, through each relevant ISP next hop.
If the Management Server is reachable only through MPLS or another private network, configure the required route through the relevant private path.
|
|
Best Practice - Monitor the next hop for each management path, so that the Security Gateway can fail over to another available path when the active path fails. |
4.5 Management-Initiated Policy Installation Connectivity
When the Management Server installs policy, it initiates a connection to the Security Gateway.
In Smart-1 Unified Management deployments, the Management Server can use the IP addresses configured on SD-WAN interfaces in the Security Gateway object, if the main management IP address is unreachable.
The Management Server tries the configured IP addresses on SD-WAN interfaces one by one.
If the Management Server fails to establish a TCP connection with first IP address, it tries the next IP address until the connection succeeds or all configured IP addresses on SD-WAN interfaces were tried.
|
|
Note - The return traffic will return symmetrically from the same external interface for SD-WAN interfaces where Symmetric Return is enabled (this is the default). |
|
|
Important - The Management Server attempts policy installation only through the IP addresses configured on SD-WAN interfaces in the Security Gateway object. If the interface is behind NAT, this fallback does not initiate the connection to the translated NAT IP address. |