Notes on SD-WAN Overlay Templates and Deployment

Jul 4, 2024

SD-WAN Overlay Templates and Deployment

Introduction

  • Industry's simple yet powerful solutions for deploying SD-WAN networks.
  • Included at no extra cost starting with FortiManager 7.2.
  • Designed for users of all technical backgrounds.
  • Utilizes best practices for every deployment.

Demo Overview

  • Objective: Deploy a large corporate SD-WAN network in a few minutes.
  • Scenario: Set up SD-WAN across corporate office, private workloads, remote branches.
    • Remote branches need to access a data center and communicate with each other.
    • Hubs located in two geo-redundant data centers for redundancy.
    • All locations to have dual ISP links for full mesh overlay network.

Steps for Deployment

  1. Login to FortiManager
    • Create SD-WAN overlay with two hubs and two branches.
    • Ensure all branches in a region are in the same device group.
    • Basic configuration: IP addresses assigned to interfaces.
  2. Provisioning Templates in Device Manager
    • Navigate to SD-WAN Overlay tab.
    • Use 4-step wizard to create SD-WAN overlay for North America region.

Four-Step Wizard

  1. Define Topology
    • Choose dual hub (primary & secondary) for active-passive setup.
    • Enable on-demand branch-to-branch tunnels for full mesh communication.
    • Enable auto-discovery VPN.
  2. Select Primary and Secondary Hubs
    • Use drop-down menu to select primary and secondary hubs.
    • Choose device group for branches.
    • Enable auto ID assignment for branch FortiGates.
  3. Define Ports for Hubs and Branches
    • Enter port information for WAN underlays (e.g., Port 1, Port 2 for Hub 1).
    • Specify port for advertisement to the network (e.g., Port 3 for Hub 1).
    • Repeat for Hub 2 and branches.
  4. Overlay Building Process
    • Associate region with existing SD-WAN template and policies.
    • Review changes and click finish.

Post-Wizard Steps

  • Template Groups: Automatically generated BGP and IPsec templates for overlay.
  • Installation: Install template groups and policies to FortiGates in FortiManager.
    • Install configuration for new interfaces first.
    • Install Hub policies next.
    • Install Branch device settings and policy packages.
  • Monitoring: Navigate to monitor section to see the SD-WAN overlay status.
    • Access key information like routing tables from FortiGate view.

Conclusion

  • Successfully created an SD-WAN overlay in minutes.
  • Like and subscribe for more videos.