Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

Create a tenant VPN for onboarded tenants using a template

Want to summarize with AI?

Log in

Describes how a provider admin creates tenant service VPNs on a multitenant WAN edge device using a Cisco VPN template, including mapping each tenant VPN ID to a device VPN ID to keep tenant traffic isolated.


After onboarding a tenant to a multitenant WAN edge device, use the Cisco VPN template to create tenant VPNs. To isolate VPN traffic of one tenant from the VPN traffic of other tenants onboarded on the multitenant WAN edge device, Cisco SD-WAN Manager maps a tenant VPN ID to a device VPN ID while you create the tenant VPN.

When you attempt to apply the tenant VPN configuration to a device, Cisco SD-WAN Manager checks these:

  • Maximum number of tenant VPNs

    The number of tenant VPNs that can be created for a tenant is restricted by the maximum number of the VPNs that is specified by the tier to which the tenant belongs. If the maximum number of tenant VPNs is already created for the tenant, Cisco SD-WAN Manager reports an error and does not apply the VPN configuration to the device.

  • Maximum number of device VPNs

    Each device model supports a certain maximum number of device VPNs. On a multitenant WAN edge device, each tenant VPN is mapped to device VPN. If the maximum number of device VPNs supported by the device are already created and mapped to tenant VPNs, Cisco SD-WAN Manager reports an error and does not apply the configuration to the device.

Before you begin

Follow these steps to create a tenant VPN for onboarded tenants.

Procedure

1.

Log in to Cisco SD-WAN Manager as the provider admin user.

2.

From the Cisco SD-WAN Manager menu, choose Configuration > Templates.

3.

Find the Device template for the multitenant WAN edge device to which you wish to onboard tenants.

4.

For the device template, click and select Edit.

This displays the device template.

5.

Click Service VPN.

6.

In the Service VPN area, click Add VPN.

7.

In the Add VPN slide-in pane, click Create VPN Template.

8.

In the Create VPN Template slide-in pane, do the following:

  1. Enter a unique template name. The template name can contain up to 128 alphanumeric characters.

  2. Enter a description for the template. The description can contain up to 2048 alphanumeric characters.

  3. In the Basic Configuration area, map the tenant VPN ID to a device VPN ID:

    1. From drop-down list corresponding to Tenant VPN, select the tenant organization name.

    2. In the text field corresponding to Tenant VPN, enter the tenant VPN ID.

    3. Click Generate VPN ID.

      A read-only VPN field displays the device VPN ID for the tenant VPN ID. SD-WAN Manager performs this mapping. For a tenant, SD-WAN Manager maps a particular tenant VPN ID to the same device VPN ID on all the multitenant WAN edge devices.

  4. Configure other properties of the tenant VPN in the template.

  5. Click Save.

9.

In the Add VPN slide-in pane, move the template created in Step 8 from Available VPN Templates to Selected VPN Templates.

10.

Click Next.

11.

Add any additional Cisco VPN templates as needed.

12.

Click Add.

13.

For the device template, click Update to save and apply the modified configuration.

14.

Select the target device in the left pane and click Configure Devices.