04-03-2023 09:04 PM
Hi All,
Just wanting to know if it is possible to deploy the Vedges with a firewall behind them?
Has anyone done this before ?
Are there any caveats or issues with this deployment type?
Basically looking to use a Palo behind the Vedges.
Appreciate some feedback.
Solved! Go to Solution.
04-04-2023 02:46 AM
Hi,
firewall behind router or router behind firewall?
If firewall behind router, it works as normal - no caveats actually (just allow respective user traffic flows on firewall).
But if router behind firewall, then you should allow respective ports. Plus, if router in configuration has private IP, but it is then mapped to public IP (through NAT), then you should have either 1:1 NAT or at least one router with 1:1 or direct public IP.
If two site routers both are behind firewall and they gt public IP through dynamic NAT/PAT, then ipsec and bfd don't come up between these sites.
See: Firewall Port Considerations section and NAT from CVD
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html#NAT
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html#FirewallPortConsiderations
04-04-2023 02:46 AM
Hi,
firewall behind router or router behind firewall?
If firewall behind router, it works as normal - no caveats actually (just allow respective user traffic flows on firewall).
But if router behind firewall, then you should allow respective ports. Plus, if router in configuration has private IP, but it is then mapped to public IP (through NAT), then you should have either 1:1 NAT or at least one router with 1:1 or direct public IP.
If two site routers both are behind firewall and they gt public IP through dynamic NAT/PAT, then ipsec and bfd don't come up between these sites.
See: Firewall Port Considerations section and NAT from CVD
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html#NAT
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-design-guide.html#FirewallPortConsiderations
04-04-2023 11:36 PM
Thanks for the docs as well. will have a read.
04-04-2023 11:35 PM
Many thanks @Kanan Huseynli
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide