Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

PDF

Restrictions for multitenancy

Want to summarize with AI?

Log in

Outlines operational and deployment restrictions associated with Cisco Catalyst SD-WAN multitenancy, guiding users to avoid unsupported configurations.


Defines the limitations and unsupported configurations in a multitenant Cisco SD-WAN deployment.

  • Connecting to a device by SSH

    Do not use a user-configured system IP address to connect to a device through SSH. Instead, use the IP address of the vmanage_system interface; this IP address is assigned by SD-WAN Manager.

  • IP address of the vmanage_system interface

    To find the IP address of the vmanage_system interface, use only one of these methods:

    • Launch the device SSH terminal from SD-WAN Manager and find the vmanage_system IP address from the first line of the log-in prompt, or

    • Run the show interface description command and find the vmanage_system IP address from the command output.

    • If you add a second tenant immediately after adding a tenant, SD-WAN Manager adds them sequentially, and not in parallel.

    • If you are adding a WAN edge device that you had previously invalidated and deleted from an overlay network, you must reset the device software after adding the device.

      To reset the software on a Cisco IOS XE Catalyst SD-WAN device, use the command, request platform software sdwan software reset .

    • For Cisco IOS XE Catalyst SD-WAN Release 17.12.1a and earlier releases, single-node SD-WAN Manager is not supported on a multitenant deployment.

      • A minimum of a 3-node SD-WAN Managercluster is required for a multitenant deployment.

  • Upgrading devices during SD-WAN Controller or SD-WAN Validator upgrade

    When a SD-WAN Controller or SD-WAN Validator upgrade is in progress, upgrade of tenant edge devices is not supported.

  • SD-WAN Controller group feature

    The SD-WAN Controller group feature is not supported in multitenant mode.

  • Device site ID

    The WAN edge device's site ID must be different from the SD-WAN Control Components site ID when the SD-WAN Manager has different public and private IP addresses.

  • Cannot change a SD-WAN Manager back to single tenant mode

    After you enable SD-WAN Manager for multitenancy, you cannot change it back to single tenant mode.