8. Configure the SD-WAN Policy

The SD-WAN Policy is a shared policy in SmartConsole. You configure it in Shared Policies, and the Management Server installs it as part of the Access Control policy installation flow.

8.1 Create the SD-WAN Policy

  1. From the left navigation panel, click Security Policies.

  2. In the Shared Policies section, click SD-WAN Policy.

  3. If no SD-WAN Policy exists, click Create Policy.

  4. On the Create SD-WAN Policy page, select the required use cases.

  5. If the environment does not require Overlay, clear Enable SD-WAN Overlay Traffic to reduce unnecessary rules.

  6. Click Create Policy.

Note - A default global Local Breakout rule, which will affect all outbound Internet traffic, is created by default and cannot be cleared on the Create Policy page. You can delete it later, if required.

If all use cases are selected, the default policy contains:

  1. Local Breakout rules for Web Conferencing and File Sharing.

  2. Overlay rules for File Sharing and Remote Access.

  3. A default Overlay catch-all rule.

  4. A default Breakout catch-all rule.

8.2 SD-WAN Policy Columns

Column

Purpose

Name

Rule name.

Source

Source objects that match the traffic.

Destination

Destination objects that match the traffic.

Services & Applications

Services, applications, application categories,

and DSCP Service Classes that match the traffic.

Steering

Steering object or Bypass action.

Translated Source

NAT behavior for the matched traffic.

QoS

QoS profile for the matched traffic.

Note - By default, the QoS column is hidden.

Right-click the column area to enable it.

Install On

Policy installation targets.

Comment

Administrative comments.

Note - By default, the Comment column is hidden.

Right-click the column area to enable it.

8.3 Supported Objects by Column

Column

Supported objects

Source

and

Destination

  • Host

  • Network

  • Address Range

  • Security Zone

  • Dynamic Object

  • Domain

  • Security Gateway Object

  • Cluster Object

  • Cluster Member Object

  • Network Groups

  • Access Role

  • Updatable Objects

  • None

Services & Applications

  • TCP service

  • UDP service

  • Other service

  • SCTP service

  • Service Group

  • Check Point Applications

  • Application Categories

  • Application/Site Group

  • Custom Application/Site

  • DSCP Service Class

  • None

Steering

  • Internet Steering object

  • Overlay Steering object

  • Bypass

Translated Source

  • User-defined NAT object

  • According to Access NAT Policy

QoS

  • User-defined QoS objects

  • Default QoS

Note - SD-WAN supports Updatable Objects documented in sk131852.

8.4 Topology Derived Objects

Topology Derived Objects are predefined objects you can use in the SD-WAN Policy to match traffic based on Security Gateway topology, VPN Domain information, VPN peer information, and "SD-WAN Internet" classification.

Use Topology Derived Objects to avoid creating and maintaining static objects for ranges that can change according to the installed policy, VPN Community, Security Gateway topology, routing information, or peer configuration.

Important - You can use Topology Derived Objects only in the SD-WAN Policy.

Supported Topology Derived Objects

Dynamic Object

Recommended Use

Description

My VPN Domain

Use in SD-WAN rules that use an Overlay Steering object.

Represents the local VPN Encryption Domain and other locally derived VPN-related address ranges on the Security Gateway.

Peer VPN Domain

Use in SD-WAN rules that use an Overlay Steering object.

Represents the combined VPN Encryption Domains and other derived VPN-related address ranges of the SD-WAN VPN peers known to the Security Gateway.

SD-WAN Internet

Use in SD-WAN rules that use Internet Steering objects, such as Local Breakout Only, Backhaul Only, and Prioritize Local Breakout.

Represents Internet destinations from the Security Gateway perspective.

Topology Derived Object "My VPN Domain"

The Topology Derived Object "My VPN Domain" represents IP address ranges considered part of the local Encryption Domain from the Security Gateway's perspective.

The object "My VPN Domain" also represents the IP addresses of the external interfaces on the local Security Gateway that establish Site-to-Site VPN tunnels.

The content of the object "My VPN Domain" depends on the VPN type:

VPN Type

Description

Domain-Based VPN

The object "My VPN Domain" includes the local VPN Encryption Domain as defined in the Access Control policy.

In Domain-Based VPN, the object "My VPN Domain" supports both IPv4 and IPv6 addresses.

If VPN Routing in a VPN Community is configured as "Route all traffic through center":

  • For IPv4, the RFC 1918 private address ranges are also included in "My VPN Domain" on the Security Gateway configured as the center.

  • For IPv6, the Unique Local Address (ULA) range fc00::/7 is also included in "My VPN Domain" on the Security Gateway configured as the center.

These IP address ranges provide additional coverage for internal networks that are not explicitly included in the configured VPN Encryption Domain.

Route-Based VPN

The object "My VPN Domain" includes directly connected routes and non-default static and dynamic routes whose outgoing interfaces are not defined as "External".

The object "My VPN Domain" also includes the IPv4 addresses configured on the local VTI on the Security Gateway.

Note - The Route-Based VPN derivation for "My VPN Domain" supports only IPv4 addresses.

Use the Topology Derived Object "My VPN Domain" in SD-WAN Policy rules that use an Overlay Steering object.

Typical use:

Column

Value

Source

My VPN Domain

Destination

Peer VPN Domain

Steering

Overlay Steering object

The Topology Derived Object "My VPN Domain" can match traffic between VPN peers, including Overlay probing traffic.

Note - No manual SD-WAN Policy rule is required for Overlay probing when the default Overlay rule already matches this traffic. The Access Control policy must still allow the required probing traffic.

Viewing the Resolved IP Ranges

  1. Connect to the command line on the Security Gateway.

  2. Run these commands to view the IP address ranges that "My VPN Domain" currently represents:

    fw tab -t sdwan_my_domain_ranges1 -u

    fw tab -t sdwan_my_domain_ranges2 -u

    Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.

Topology Derived Object "Peer VPN Domain"

The Topology Derived Object "Peer VPN Domain" represents IP address ranges considered part of the VPN Encryption Domains of the SD-WAN VPN peers known to the Security Gateway.

The object "Peer VPN Domain" also represents the IP addresses of the external interfaces on these peer Security Gateways that establish Site-to-Site VPN tunnels.

The content of the object "Peer VPN Domain" depends on the VPN type:

VPN Type

Description

Domain-Based VPN

The object "Peer VPN Domain" includes the VPN Encryption Domains of the SD-WAN VPN peers as defined in the Access Control policy.

In Domain-Based VPN, the object "Peer VPN Domain" supports both IPv4 and IPv6 addresses.

If VPN Routing in a VPN Community is configured as "Route all traffic through center":

  • For IPv4, the RFC 1918 private address ranges are also included in "Peer VPN Domain" on the Security Gateway configured as satellites.

  • For IPv6, the Unique Local Address (ULA) range fc00::/7 is also included in "Peer VPN Domain" on the Security Gateway configured as satellites.

These IP address ranges provide additional coverage for internal networks behind the center that are not explicitly included in its configured VPN Encryption Domain.

Route-Based VPN

The object "Peer VPN Domain" includes non-default static and dynamic routes whose outgoing interfaces are VTIs.

The object "Peer VPN Domain" also includes the IPv4 addresses of the VTIs on all SD-WAN VPN peers known to the Security Gateway.

Note - The Route-Based VPN derivation for "Peer VPN Domain" supports only IPv4 addresses.

When a default route is configured toward a VTI:

  • The RFC 1918 private IPv4 address ranges are also included in "Peer VPN Domain" on that Security Gateway.

  • IPv6 address ranges are not added.

Use the Topology Derived Object "Peer VPN Domain" in SD-WAN Policy rules that use an Overlay Steering object.

Typical use:

Column

Value

Source

My VPN Domain

Destination

Peer VPN Domain

Steering

Overlay Steering object

The Topology Derived Object "Peer VPN Domain" can match traffic between VPN peers, including Overlay probing traffic.

Note - No manual SD-WAN Policy rule is required for Overlay probing when the default Overlay rule already matches this traffic. The Access Control policy must still allow the required probing traffic.

Viewing the Resolved IP Ranges

  1. Connect to the command line on the Security Gateway.

  2. Run these commands to view the IP address ranges that "Peer VPN Domain" currently represents:

    fw tab -t sdwan_peer_domain_ranges1 -u

    fw tab -t sdwan_peer_domain_ranges2 -u

    Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.

Topology Derived Object "SD-WAN Internet"

The Topology Derived Object "SD-WAN Internet" represents Internet destinations from the Security Gateway perspective.

The object "SD-WAN Internet" supports both IPv4 and IPv6 addresses.

Use the Topology Derived Object "SD-WAN Internet" in SD-WAN Policy rules that use Internet Steering objects, such as Local Breakout Only, Backhaul Only, and Prioritize Local Breakout.

Typical use:

Column

Value

Source

Internal networks, Access Role, users, or groups

Destination

SD-WAN Internet

Steering

Internet Steering object

The Topology Derived Object "SD-WAN Internet" excludes IP address ranges that are not considered Internet destinations from the Security Gateway local perspective.

The object "SD-WAN Internet" excludes these IP addresses:

IP

Value

IPv4

  • Reserved IP address ranges, such as private, public-reserved, and multicast ranges.

  • IP addresses of networks that are directly connected to the Security Gateway.

  • Cluster Virtual IP addresses.

  • IP address ranges of the local VPN Encryption Domain.

  • IP address ranges of the VPN Encryption Domains of all VPN peers known to the Security Gateway, including peers that are not SD-WAN peers.

  • When Route-Based VPN is configured on the Security Gateway (at least one VTI is configured), ranges of public IPv4 addresses, for which non-default static or dynamic routes lead to Internal or VTIs.

IPv6

  • Special-purpose IPv6 address ranges, such as local, reserved, documentation, translation, and other non-publicly routable ranges.

  • IPv6 addresses of networks that are directly connected to the Security Gateway.

  • Cluster Virtual IP addresses.

  • IPv6 address ranges of the local VPN Encryption Domain.

  • IPv6 address ranges of the VPN Encryption Domains of all VPN peers known to the Security Gateway, including peers that are not SD-WAN peers.

Viewing the Resolved IP Ranges

  1. Connect to the command line on the Security Gateway.

  2. Run these commands to view the IP address ranges that "SD-WAN Internet" currently represents:

    fw tab -t sdwan_internet_ranges1 -u

    fw tab -t sdwan_internet_ranges2 -u

    Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.

Destination NAT Behavior with "SD-WAN Internet"

For connections that undergo Destination NAT, such as inbound NAT or traffic to published services, SD-WAN Policy matching against "SD-WAN Internet" is done after Destination NAT.

This means:

Post-NAT Destination

Result

The destination IP address after NAT matches "SD-WAN Internet".

The connection can match the SD-WAN rule that uses "SD-WAN Internet".

The destination IP address after NAT does not match "SD-WAN Internet", for example because it is private or belongs to a directly connected network.

The connection does not match the SD-WAN rule that uses "SD-WAN Internet".

Important - For Local Breakout and Backhaul rules, use "SD-WAN Internet" in the "Destination" column when possible. Do not use "*Any" unless the rule is intentionally designed to match non-Internet destinations as well.

Best Practices for SD-WAN Topology Derived Objects

  • For Internet Steering rules, use "SD-WAN Internet" in the "Destination" column when possible.

  • For Overlay Steering rules, use "My VPN Domain" and "Peer VPN Domain" when possible.

  • Place more specific SD-WAN rules above more general rules.

  • If the organization uses public IP addresses internally, for example in DMZ networks, VoIP networks, inbound NAT pools, or MPLS-connected sites, make sure these ranges do not unintentionally match Internet Steering rules. If needed, create a more specific rule above the Internet rule and use an Overlay Steering object or Bypass according to the required behavior.

8.5 Steering Actions

Action / object

Behavior

Internet Steering

Steers outbound Internet traffic according to the selected routing preference, candidates, criteria, and quality check settings.

Overlay Steering

Steers overlay traffic between SD-WAN peers according to candidates, criteria, and quality check settings.

Bypass

Read-only object that bypasses SD-WAN for matching traffic.

The behavior is the same as if the traffic did not match an SD-WAN rule.

Important - When you select Bypass in the Steering column, it is not supported to configure a user-defined NAT object or QoS object in the same SD-WAN rule.

8.6 Policy Defaults

Field

Default when creating a new rule / Last in Cell removal

Source

None

Destination

None

Services & Applications

None

Steering

Bypass

Translated Source

According to Access NAT Policy

QoS

Default QoS

Install On

Policy Targets

Note - These settings are currently not affected by SmartConsole > Manage & Settings > Policy Settings.

8.7 Supported Rule-Base Operations

Supported Operations

Not Supported Operations

Drag and drop objects between rules

Drag an object from the object tree into the SD-WAN rule base

Drag and drop SD-WAN rules

Copy, cut, or paste rules

Disable a rule

Create inline layers or ordered layers

Create section titles

Select multiple rules

Search the rule base

Create a new object from within the Source, Destination, or Service picker

Use a user-defined NAT object or QoS object when Steering is Bypass

Delete a rule with keyboard shortcut