cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
809
Views
5
Helpful
4
Replies

SDWAN cEdge ZBFW Policies

configt
Level 1
Level 1

In the process of deploying cEdge to all our branches and working through our templates in test first.

 

We want to introduce segmentation at the branch leveraging the ZBFW.  Trying to determine if we place all our SVI into same VPN and leverage FW rules or each SVI in separate VPN and leverage FW.  Will the FW connect separate VPN locally that way?

 

lastly when testing FW rules between L3 VLANs in same VPN the FW rules do not seem to work.  Or even FW rules from VPN1 to VPN0.  Feel I’m missing something obvious here.

 

thank you

1 Accepted Solution

Accepted Solutions

You can assign any SVI/Sub-Interface to any VPN/VRF you want. They won't be able to talk to one another obviously but that's when you need to then leverage the ZBFW aspect and then allow each Zone/VPN to talk to another if needed. 

For example, one of my segmented VPNs is allocated for Guest. I have 2 Zone Pairs for its connection. ZPair1- I "Inspect" Guest access to the Internet Zone "VPN0",  but only allowing traffic sourcing from my Guest subnets and also matching protocols, "1","6","17".  ZPair2 - I then Drop all traffic Sourcing from Internet Zone to Guest Zone. 

If you want to allow some IPs to reach another IP in another zone, then you'll need to Route Leak via Centralized Policy/Topology Sequence type Route. 

I hope I answered your question. Let me know if anything I said was unclear. 

***Please remember to "Accept as Solution" if I answered correctly***

View solution in original post

4 Replies 4

You can assign any SVI/Sub-Interface to any VPN/VRF you want. They won't be able to talk to one another obviously but that's when you need to then leverage the ZBFW aspect and then allow each Zone/VPN to talk to another if needed. 

For example, one of my segmented VPNs is allocated for Guest. I have 2 Zone Pairs for its connection. ZPair1- I "Inspect" Guest access to the Internet Zone "VPN0",  but only allowing traffic sourcing from my Guest subnets and also matching protocols, "1","6","17".  ZPair2 - I then Drop all traffic Sourcing from Internet Zone to Guest Zone. 

If you want to allow some IPs to reach another IP in another zone, then you'll need to Route Leak via Centralized Policy/Topology Sequence type Route. 

I hope I answered your question. Let me know if anything I said was unclear. 

***Please remember to "Accept as Solution" if I answered correctly***

Appreciate the response and information.  Was able to test it all out some more and come up with an acceptable solution with SVI in same service VPN.  We have Guest services as well but have not had an opportunity to test that configuration out.  You mentioned having to put a rule from internet zone back into guest zone to drop, is that necessary to explicitly define that if default action for ruleset is drop?

I forgot what the document states but I added the Zone Pair to address the Zone communication and if anything tries to communicate inwards to my VPNs, it will drop. 

Is it necessary, no, is it best practice, yes. You can never be too sure. BTW, I have this same "Drop" rule for all my VPNs coming inbound from VPN0 aka Internet Zone. 

Much appreciated