8. Configure the SD-WAN Policy
The SD-WAN Policy is a shared policy in SmartConsole. You configure it in Shared Policies, and the Management Server installs it as part of the Access Control policy installation flow.
8.1 Create the SD-WAN Policy
-
From the left navigation panel, click Security Policies.
-
In the Shared Policies section, click SD-WAN Policy.
-
If no SD-WAN Policy exists, click Create Policy.
-
On the Create SD-WAN Policy page, select the required use cases.
-
If the environment does not require , clear Enable SD-WAN Traffic to reduce unnecessary rules.
-
Click Create Policy.
|
|
Note - A default global Local Breakout rule, which will affect all outbound Internet traffic, is created by default and cannot be cleared on the Create Policy page. You can delete it later, if required. |
If all use cases are selected, the default policy contains:
-
Local Breakout rules for Web Conferencing and File Sharing.
-
rules for File Sharing and Remote Access.
-
A default catch-all rule.
-
A default Breakout catch-all rule.
8.2 SD-WAN Policy Columns
|
Column |
Purpose |
||
|---|---|---|---|
|
Name |
Rule name. |
||
|
Source |
Source objects that match the traffic. |
||
|
Destination |
Destination objects that match the traffic. |
||
|
Services & Applications |
Services, applications, application categories, and DSCP Service Classes that match the traffic. |
||
|
Steering |
Steering object or Bypass action. |
||
|
Translated Source |
NAT behavior for the matched traffic. |
||
|
QoS |
QoS profile for the matched traffic.
|
||
|
Install On |
Policy installation targets. |
||
|
Comment |
Administrative comments.
|
8.3 Supported Objects by Column
|
Column |
Supported objects |
|---|---|
|
Source and Destination |
|
|
Services & Applications |
|
|
Steering |
|
|
Translated Source |
|
|
QoS |
|
|
|
Note - SD-WAN supports Updatable Objects documented in sk131852. |
8.4 Topology Derived Objects
Topology Derived Objects are predefined objects you can use in the SD-WAN Policy to match traffic based on Security Gateway topology, VPN Domain information, VPN peer information, and "SD-WAN Internet" classification.
Use Topology Derived Objects to avoid creating and maintaining static objects for ranges that can change according to the installed policy, VPN Community, Security Gateway topology, routing information, or peer configuration.
|
|
Important - You can use Topology Derived Objects only in the SD-WAN Policy. |
Supported Topology Derived Objects
|
Dynamic Object |
Recommended Use |
Description |
|---|---|---|
|
|
Use in SD-WAN rules that use an Steering object. |
Represents the local VPN Encryption Domain and other locally derived VPN-related address ranges on the Security Gateway. |
|
|
Use in SD-WAN rules that use an Steering object. |
Represents the combined VPN Encryption Domains and other derived VPN-related address ranges of the SD-WAN VPN peers known to the Security Gateway. |
|
|
Use in SD-WAN rules that use Internet Steering objects, such as Local Breakout Only, Backhaul Only, and Prioritize Local Breakout. |
Represents Internet destinations from the Security Gateway perspective. |
Topology Derived Object "My VPN Domain"
The Topology Derived Object "My VPN Domain" represents IP address ranges considered part of the local Encryption Domain from the Security Gateway's perspective.
The object "My VPN Domain" also represents the IP addresses of the external interfaces on the local Security Gateway that establish Site-to-Site VPN tunnels.
The content of the object "My VPN Domain" depends on the VPN type:
|
VPN Type |
Description |
|---|---|
|
Domain-Based VPN |
The object "My VPN Domain" includes the local VPN Encryption Domain as defined in the Access Control policy. In Domain-Based VPN, the object "My VPN Domain" supports both IPv4 and IPv6 addresses. If VPN Routing in a VPN Community is configured as "Route all traffic through center":
These IP address ranges provide additional coverage for internal networks that are not explicitly included in the configured VPN Encryption Domain. |
|
Route-Based VPN |
The object "My VPN Domain" includes directly connected routes and non-default static and dynamic routes whose outgoing interfaces are not defined as "External". The object "My VPN Domain" also includes the IPv4 addresses configured on the local VTI on the Security Gateway. Note - The Route-Based VPN derivation for "My VPN Domain" supports only IPv4 addresses. |
Use the Topology Derived Object "My VPN Domain" in SD-WAN Policy rules that use an Steering object.
Typical use:
|
Column |
Value |
|---|---|
|
Source |
|
|
Destination |
|
|
Steering |
Steering object |
The Topology Derived Object "My VPN Domain" can match traffic between VPN peers, including probing traffic.
|
|
Note - No manual SD-WAN Policy rule is required for probing when the default rule already matches this traffic. The Access Control policy must still allow the required probing traffic. |
Viewing the Resolved IP Ranges
-
Connect to the command line on the Security Gateway.
-
Run these commands to view the IP address ranges that "My VPN Domain" currently represents:
fw tab -t sdwan_my_domain_ranges1 -ufw tab -t sdwan_my_domain_ranges2 -u
Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.
Topology Derived Object "Peer VPN Domain"
The Topology Derived Object "Peer VPN Domain" represents IP address ranges considered part of the VPN Encryption Domains of the SD-WAN VPN peers known to the Security Gateway.
The object "Peer VPN Domain" also represents the IP addresses of the external interfaces on these peer Security Gateways that establish Site-to-Site VPN tunnels.
The content of the object "Peer VPN Domain" depends on the VPN type:
|
VPN Type |
Description |
|---|---|
|
Domain-Based VPN |
The object "Peer VPN Domain" includes the VPN Encryption Domains of the SD-WAN VPN peers as defined in the Access Control policy. In Domain-Based VPN, the object "Peer VPN Domain" supports both IPv4 and IPv6 addresses. If VPN Routing in a VPN Community is configured as "Route all traffic through center":
These IP address ranges provide additional coverage for internal networks behind the center that are not explicitly included in its configured VPN Encryption Domain. |
|
Route-Based VPN |
The object "Peer VPN Domain" includes non-default static and dynamic routes whose outgoing interfaces are VTIs. The object "Peer VPN Domain" also includes the IPv4 addresses of the VTIs on all SD-WAN VPN peers known to the Security Gateway. Note - The Route-Based VPN derivation for "Peer VPN Domain" supports only IPv4 addresses. |
When a default route is configured toward a VTI:
-
The RFC 1918 private IPv4 address ranges are also included in "Peer VPN Domain" on that Security Gateway.
-
IPv6 address ranges are not added.
Use the Topology Derived Object "Peer VPN Domain" in SD-WAN Policy rules that use an Steering object.
Typical use:
|
Column |
Value |
|---|---|
|
Source |
|
|
Destination |
|
|
Steering |
Steering object |
The Topology Derived Object "Peer VPN Domain" can match traffic between VPN peers, including probing traffic.
|
|
Note - No manual SD-WAN Policy rule is required for probing when the default rule already matches this traffic. The Access Control policy must still allow the required probing traffic. |
Viewing the Resolved IP Ranges
-
Connect to the command line on the Security Gateway.
-
Run these commands to view the IP address ranges that "Peer VPN Domain" currently represents:
fw tab -t sdwan_peer_domain_ranges1 -ufw tab -t sdwan_peer_domain_ranges2 -u
Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.
Topology Derived Object "SD-WAN Internet"
The Topology Derived Object "SD-WAN Internet" represents Internet destinations from the Security Gateway perspective.
The object "SD-WAN Internet" supports both IPv4 and IPv6 addresses.
Use the Topology Derived Object "SD-WAN Internet" in SD-WAN Policy rules that use Internet Steering objects, such as Local Breakout Only, Backhaul Only, and Prioritize Local Breakout.
Typical use:
|
Column |
Value |
|---|---|
|
Source |
Internal networks, Access Role, users, or groups |
|
Destination |
|
|
Steering |
Internet Steering object |
The Topology Derived Object "SD-WAN Internet" excludes IP address ranges that are not considered Internet destinations from the Security Gateway local perspective.
The object "SD-WAN Internet" excludes these IP addresses:
|
IP |
Value |
|---|---|
|
IPv4 |
|
|
IPv6 |
|
Viewing the Resolved IP Ranges
-
Connect to the command line on the Security Gateway.
-
Run these commands to view the IP address ranges that "SD-WAN Internet" currently represents:
fw tab -t sdwan_internet_ranges1 -ufw tab -t sdwan_internet_ranges2 -u
Note - At any given time, only one of these kernel tables contains the active IP address ranges. The other table is empty.
Destination NAT Behavior with "SD-WAN Internet"
For connections that undergo Destination NAT, such as inbound NAT or traffic to published services, SD-WAN Policy matching against "SD-WAN Internet" is done after Destination NAT.
This means:
|
Post-NAT Destination |
Result |
|---|---|
|
The destination IP address after NAT matches "SD-WAN Internet". |
The connection can match the SD-WAN rule that uses "SD-WAN Internet". |
|
The destination IP address after NAT does not match "SD-WAN Internet", for example because it is private or belongs to a directly connected network. |
The connection does not match the SD-WAN rule that uses "SD-WAN Internet". |
|
|
Important - For Local Breakout and Backhaul rules, use "SD-WAN Internet" in the "Destination" column when possible. Do not use " |
Best Practices for SD-WAN Topology Derived Objects
-
For Internet Steering rules, use "SD-WAN Internet" in the "Destination" column when possible.
-
For Steering rules, use "My VPN Domain" and "Peer VPN Domain" when possible.
-
Place more specific SD-WAN rules above more general rules.
-
If the organization uses public IP addresses internally, for example in DMZ networks, VoIP networks, inbound NAT pools, or MPLS-connected sites, make sure these ranges do not unintentionally match Internet Steering rules. If needed, create a more specific rule above the Internet rule and use an Steering object or Bypass according to the required behavior.
8.5 Steering Actions
|
Action / object |
Behavior |
|---|---|
|
Internet Steering |
Steers outbound Internet traffic according to the selected routing preference, candidates, criteria, and quality check settings. |
|
Steering |
Steers overlay traffic between SD-WAN peers according to candidates, criteria, and quality check settings. |
|
Bypass |
Read-only object that bypasses SD-WAN for matching traffic. The behavior is the same as if the traffic did not match an SD-WAN rule. |
|
|
Important - When you select Bypass in the Steering column, it is not supported to configure a user-defined NAT object or QoS object in the same SD-WAN rule. |
8.6 Policy Defaults
|
Field |
Default when creating a new rule / Last in Cell removal |
|---|---|
|
Source |
None |
|
Destination |
None |
|
Services & Applications |
None |
|
Steering |
Bypass |
|
Translated Source |
According to Access NAT Policy |
|
QoS |
Default QoS |
|
Install On |
Policy Targets |
|
|
Note - These settings are currently not affected by SmartConsole > Manage & Settings > Policy Settings. |
8.7 Supported Rule-Base Operations
|
Supported Operations |
Not Supported Operations |
|---|---|
|
Drag and drop objects between rules |
Drag an object from the object tree into the SD-WAN rule base |
|
Drag and drop SD-WAN rules |
Copy, cut, or paste rules |
|
Disable a rule |
Create inline layers or ordered layers |
|
Create section titles |
Select multiple rules |
|
Search the rule base |
Create a new object from within the Source, Destination, or Service picker |
|
|
Use a user-defined NAT object or QoS object when Steering is Bypass |
|
|
Delete a rule with keyboard shortcut |